labkey records
6 published records for vendor labkey.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2019-9757Proof of concept | An issue was discovered in LabKey Server 19.1.0.labkey · labkey server · CWE-611 | High7.5 | — | 37.3% | Oct 29, 2019 |
36Monitor | CVE-2019-9926No exploit | An issue was discovered in LabKey Server 19.1.0.labkey · labkey server · CWE-352 | High8.8 | — | 1.9% | Oct 29, 2019 |
25Monitor | CVE-2019-3912Proof of concept | An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unautlabkey · labkey server · CWE-601 | Medium6.1 | — | 4.8% | Jan 30, 2019 |
25Monitor | CVE-2019-3911Proof of concept | Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remolabkey · labkey server · CWE-79 | Medium6.1 | — | 3.8% | Jan 30, 2019 |
21Monitor | CVE-2019-9758No exploit | An issue was discovered in LabKey Server 19.1.0.labkey · labkey server · CWE-79 | Medium5.4 | — | 1.0% | Oct 29, 2019 |
20Monitor | CVE-2019-3913No exploit | Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drivelabkey · labkey server · CWE-77 | Medium4.9 | — | 1.7% | Jan 30, 2019 |
- CVE-2019-975741Plan
An issue was discovered in LabKey Server 19.1.0.
HighCVSS 7.5Proof of conceptEPSS 37%labkey · labkey serverOct 29, 2019
- CVE-2019-992636Monitor
An issue was discovered in LabKey Server 19.1.0.
HighCVSS 8.8No exploitEPSS 2%labkey · labkey serverOct 29, 2019
- CVE-2019-391225Monitor
An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unaut
MediumCVSS 6.1Proof of conceptEPSS 5%labkey · labkey serverJan 30, 2019
- CVE-2019-391125Monitor
Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remo
MediumCVSS 6.1Proof of conceptEPSS 4%labkey · labkey serverJan 30, 2019
- CVE-2019-975821Monitor
An issue was discovered in LabKey Server 19.1.0.
MediumCVSS 5.4No exploitEPSS 1%labkey · labkey serverOct 29, 2019
- CVE-2019-391320Monitor
Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drive
MediumCVSS 4.9No exploitEPSS 2%labkey · labkey serverJan 30, 2019