mendix records
30 published records for vendor mendix.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-303 Incorrect Implementation of Authentication Algorithm2
- CWE-209 Generation of Error Message Containing Sensitive Information2
- CWE-863 Incorrect Authorization2
- CWE-294 Authentication Bypass by Capture-replay2
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
30 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-26314No exploit | A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appsmendix · forgot password · CWE-307 | Critical9.8 | — | 1.5% | Mar 8, 2022 |
39Monitor | CVE-2022-37011No exploit | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All vemendix · saml · CWE-294 | Critical9.8 | — | 1.2% | Sep 13, 2022 |
39Monitor | CVE-2022-26313No exploit | A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1).mendix · forgot password · CWE-284 | Critical9.8 | — | 1.0% | Mar 8, 2022 |
39Monitor | CVE-2023-29129No exploit | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatibmendix · saml · CWE-303 | Critical9.8 | — | 0.9% | Jun 13, 2023 |
39Monitor | CVE-2022-44457No exploit | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All vemendix · saml · CWE-294 | Critical9.8 | — | 0.7% | Nov 8, 2022 |
35Monitor | CVE-2021-25672No exploit | A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1).mendix · forgot password · CWE-284 | High8.8 | — | 0.9% | Mar 15, 2021 |
35Monitor | CVE-2021-27394No exploit | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (Allmendix · mendix · CWE-269 | High8.8 | — | 0.8% | Apr 16, 2021 |
35Monitor | CVE-2021-33712No exploit | A vulnerability has been identified in Mendix SAML Module (All versions < V2.1.2).mendix · saml · CWE-345 | High8.8 | — | 0.6% | Jun 8, 2021 |
32Monitor | CVE-2022-24309No exploit | A vulnerability has been identified in Mendix Runtime V7 (All versions < V7.23.29), Mendix Runtime V8 (All versions < V8.18.16), Mendix Runtmendix · mendix · CWE-284 | High8.1 | — | 0.6% | Mar 8, 2022 |
30Monitor | CVE-2022-27241No exploit | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (Allmendix · mendix · CWE-200 | High7.5 | — | 1.4% | Apr 12, 2022 |
30Monitor | CVE-2022-32285No exploit | A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compamendix · saml · CWE-611 | High7.5 | — | 1.0% | Jun 14, 2022 |
30Monitor | CVE-2022-31257No exploit | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (Allmendix · mendix · CWE-284 | High7.5 | — | 0.8% | Jul 12, 2022 |
30Monitor | CVE-2023-25957No exploit | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatibmendix · saml · CWE-303 | High7.5 | — | 0.6% | Mar 14, 2023 |
30Monitor | CVE-2023-23835No exploit | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (Allmendix · mendix · CWE-284 | High7.5 | — | 0.5% | Feb 14, 2023 |
27Monitor | CVE-2024-50313No exploit | A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.16.0 only if the basic authentication mechanism is used by themendix · mendix · CWE-362 | Medium6.9 | — | 0.3% | Nov 12, 2024 |
26Monitor | CVE-2022-26317No exploit | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29).mendix · mendix · CWE-284 | Medium6.5 | — | 1.0% | Mar 8, 2022 |
26Monitor | CVE-2022-34467No exploit | A vulnerability has been identified in Mendix Excel Importer Module (Mendix 8 compatible) (All versions < V9.2.2), Mendix Excel Importer Modmendix · excel importer · CWE-776 | Medium6.5 | — | 0.8% | Jul 12, 2022 |
26Monitor | CVE-2022-34466No exploit | A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix mendix · mendix · CWE-74 | Medium6.5 | — | 0.7% | Jul 12, 2022 |
26Monitor | CVE-2022-25650No exploit | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications using Mendix 8 (Allmendix · mendix · CWE-284 | Medium6.5 | — | 0.7% | Apr 12, 2022 |
26Monitor | CVE-2021-42025No exploit | A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (Allmendix · mendix · CWE-863 | Medium6.5 | — | 0.6% | Nov 9, 2021 |
24Monitor | CVE-2020-8160No exploit | MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via mendix · mendixsso · CWE-79 | Medium6.1 | — | 0.7% | Jan 6, 2021 |
24Monitor | CVE-2022-32286No exploit | A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compamendix · saml · CWE-79 | Medium6.1 | — | 0.6% | Jun 14, 2022 |
24Monitor | CVE-2022-46823No exploit | A vulnerability has been identified in Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.4), Mendix SAML (Mendix 9 compatiblemendix · saml · CWE-79 | Medium6.1 | — | 0.5% | Jan 10, 2023 |
22Monitor | CVE-2021-42015No exploit | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.26), Mendix Applications using Mendix 8 (Allmendix · mendix · CWE-525 | Medium5.5 | — | 0.2% | Nov 9, 2021 |
21Monitor | CVE-2019-12996No exploit | In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potentially unsafe.mendix · mendix · CWE-918 | Medium5.3 | — | 0.8% | Sep 10, 2019 |
- CVE-2022-2631439Monitor
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Apps
CriticalCVSS 9.8No exploitEPSS 1%mendix · forgot passwordMar 8, 2022
- CVE-2022-3701139Monitor
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All ve
CriticalCVSS 9.8No exploitEPSS 1%mendix · samlSep 13, 2022
- CVE-2022-2631339Monitor
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1).
CriticalCVSS 9.8No exploitEPSS 1%mendix · forgot passwordMar 8, 2022
- CVE-2023-2912939Monitor
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatib
CriticalCVSS 9.8No exploitEPSS 1%mendix · samlJun 13, 2023
- CVE-2022-4445739Monitor
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All ve
CriticalCVSS 9.8No exploitEPSS 1%mendix · samlNov 8, 2022
- CVE-2021-2567235Monitor
A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1).
HighCVSS 8.8No exploitEPSS 1%mendix · forgot passwordMar 15, 2021
- CVE-2021-2739435Monitor
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (All
HighCVSS 8.8No exploitEPSS 1%mendix · mendixApr 16, 2021
- CVE-2021-3371235Monitor
A vulnerability has been identified in Mendix SAML Module (All versions < V2.1.2).
HighCVSS 8.8No exploitEPSS 1%mendix · samlJun 8, 2021
- CVE-2022-2430932Monitor
A vulnerability has been identified in Mendix Runtime V7 (All versions < V7.23.29), Mendix Runtime V8 (All versions < V8.18.16), Mendix Runt
HighCVSS 8.1No exploitEPSS 1%mendix · mendixMar 8, 2022
- CVE-2022-2724130Monitor
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All
HighCVSS 7.5No exploitEPSS 1%mendix · mendixApr 12, 2022
- CVE-2022-3228530Monitor
A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compa
HighCVSS 7.5No exploitEPSS 1%mendix · samlJun 14, 2022
- CVE-2022-3125730Monitor
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All
HighCVSS 7.5No exploitEPSS 1%mendix · mendixJul 12, 2022
- CVE-2023-2595730Monitor
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatib
HighCVSS 7.5No exploitEPSS 1%mendix · samlMar 14, 2023
- CVE-2023-2383530Monitor
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All
HighCVSS 7.5No exploitEPSS 0%mendix · mendixFeb 14, 2023
- CVE-2024-5031327Monitor
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.16.0 only if the basic authentication mechanism is used by the
MediumCVSS 6.9No exploitEPSS 0%mendix · mendixNov 12, 2024
- CVE-2022-2631726Monitor
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29).
MediumCVSS 6.5No exploitEPSS 1%mendix · mendixMar 8, 2022
- CVE-2022-3446726Monitor
A vulnerability has been identified in Mendix Excel Importer Module (Mendix 8 compatible) (All versions < V9.2.2), Mendix Excel Importer Mod
MediumCVSS 6.5No exploitEPSS 1%mendix · excel importerJul 12, 2022
- CVE-2022-3446626Monitor
A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix
MediumCVSS 6.5No exploitEPSS 1%mendix · mendixJul 12, 2022
- CVE-2022-2565026Monitor
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications using Mendix 8 (All
MediumCVSS 6.5No exploitEPSS 1%mendix · mendixApr 12, 2022
- CVE-2021-4202526Monitor
A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All
MediumCVSS 6.5No exploitEPSS 1%mendix · mendixNov 9, 2021
- CVE-2020-816024Monitor
MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via
MediumCVSS 6.1No exploitEPSS 1%mendix · mendixssoJan 6, 2021
- CVE-2022-3228624Monitor
A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compa
MediumCVSS 6.1No exploitEPSS 1%mendix · samlJun 14, 2022
- CVE-2022-4682324Monitor
A vulnerability has been identified in Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.4), Mendix SAML (Mendix 9 compatible
MediumCVSS 6.1No exploitEPSS 0%mendix · samlJan 10, 2023
- CVE-2021-4201522Monitor
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.26), Mendix Applications using Mendix 8 (All
MediumCVSS 5.5No exploitEPSS 0%mendix · mendixNov 9, 2021
- CVE-2019-1299621Monitor
In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potentially unsafe.
MediumCVSS 5.3No exploitEPSS 1%mendix · mendixSep 10, 2019