mk-auth records
9 published records for vendor mk-auth.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-287 Improper Authentication1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-14072No exploit | An issue was discovered in MK-AUTH 19.01.mk-auth · mk-auth · CWE-78 | Critical9.8 | — | 3.4% | Jun 29, 2020 |
40Plan | CVE-2020-14070No exploit | An issue was discovered in MK-AUTH 19.01.mk-auth · mk-auth · CWE-287 | Critical9.8 | — | 1.8% | Jun 29, 2020 |
39Monitor | CVE-2020-14068No exploit | An issue was discovered in MK-AUTH 19.01.mk-auth · mk-auth · CWE-89 | Critical9.8 | — | 1.1% | Jun 29, 2020 |
35Monitor | CVE-2023-27246No exploit | An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a cmk-auth · mk-auth · CWE-434 | High8.8 | — | 0.8% | Mar 28, 2023 |
35Monitor | CVE-2021-21495No exploit | MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI.mk-auth · mk-auth · CWE-352 | High8.8 | — | 0.5% | Jan 3, 2021 |
27Monitor | CVE-2020-14069No exploit | An issue was discovered in MK-AUTH 19.01.mk-auth · mk-auth · CWE-89 | Medium6.8 | — | 0.4% | Jun 29, 2020 |
24Monitor | CVE-2020-14071No exploit | An issue was discovered in MK-AUTH 19.01.mk-auth · mk-auth · CWE-79 | Medium6.1 | — | 0.7% | Jun 29, 2020 |
19Monitor | CVE-2021-21494No exploit | MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter.mk-auth · mk-auth · CWE-732 | Medium4.8 | — | 0.5% | Jan 3, 2021 |
17Monitor | CVE-2021-3005No exploit | MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice nmk-auth · mk-auth | Medium4.3 | — | 0.9% | Jan 3, 2021 |
- CVE-2020-1407240Plan
An issue was discovered in MK-AUTH 19.01.
CriticalCVSS 9.8No exploitEPSS 3%mk-auth · mk-authJun 29, 2020
- CVE-2020-1407040Plan
An issue was discovered in MK-AUTH 19.01.
CriticalCVSS 9.8No exploitEPSS 2%mk-auth · mk-authJun 29, 2020
- CVE-2020-1406839Monitor
An issue was discovered in MK-AUTH 19.01.
CriticalCVSS 9.8No exploitEPSS 1%mk-auth · mk-authJun 29, 2020
- CVE-2023-2724635Monitor
An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a c
HighCVSS 8.8No exploitEPSS 1%mk-auth · mk-authMar 28, 2023
- CVE-2021-2149535Monitor
MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI.
HighCVSS 8.8No exploitEPSS 1%mk-auth · mk-authJan 3, 2021
- CVE-2020-1406927Monitor
An issue was discovered in MK-AUTH 19.01.
MediumCVSS 6.8No exploitEPSS 0%mk-auth · mk-authJun 29, 2020
- CVE-2020-1407124Monitor
An issue was discovered in MK-AUTH 19.01.
MediumCVSS 6.1No exploitEPSS 1%mk-auth · mk-authJun 29, 2020
- CVE-2021-2149419Monitor
MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter.
MediumCVSS 4.8No exploitEPSS 1%mk-auth · mk-authJan 3, 2021
- CVE-2021-300517Monitor
MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice n
MediumCVSS 4.3No exploitEPSS 1%mk-auth · mk-authJan 3, 2021