iris records
7 published records for vendor iris.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2020-28405No exploit | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to change tiris · star practice management | High8.8 | — | 1.6% | Jan 29, 2021 |
35Monitor | CVE-2020-28402No exploit | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access Liris · star practice management | High8.8 | — | 1.4% | Jan 29, 2021 |
35Monitor | CVE-2020-28403No exploit | A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change iris · star · CWE-352 | High8.8 | — | 0.7% | Jan 29, 2021 |
26Monitor | CVE-2020-28404No exploit | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access tiris · star practice management | Medium6.5 | — | 1.3% | Jan 29, 2021 |
26Monitor | CVE-2020-28401No exploit | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access Wiris · star practice management | Medium6.5 | — | 1.3% | Jan 29, 2021 |
26Monitor | CVE-2020-28406No exploit | An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access diris · star practice management | Medium6.5 | — | 1.3% | Jan 29, 2021 |
21Monitor | CVE-2022-37028No exploit | ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker to store a JavaScripiris · isams · CWE-79 | Medium5.4 | — | 0.6% | Sep 27, 2022 |
- CVE-2020-2840535Monitor
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to change t
HighCVSS 8.8No exploitEPSS 2%iris · star practice managementJan 29, 2021
- CVE-2020-2840235Monitor
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access L
HighCVSS 8.8No exploitEPSS 1%iris · star practice managementJan 29, 2021
- CVE-2020-2840335Monitor
A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change
HighCVSS 8.8No exploitEPSS 1%iris · starJan 29, 2021
- CVE-2020-2840426Monitor
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access t
MediumCVSS 6.5No exploitEPSS 1%iris · star practice managementJan 29, 2021
- CVE-2020-2840126Monitor
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access W
MediumCVSS 6.5No exploitEPSS 1%iris · star practice managementJan 29, 2021
- CVE-2020-2840626Monitor
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access d
MediumCVSS 6.5No exploitEPSS 1%iris · star practice managementJan 29, 2021
- CVE-2022-3702821Monitor
ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker to store a JavaScrip
MediumCVSS 5.4No exploitEPSS 1%iris · isamsSep 27, 2022