profelis records
3 published records for vendor profelis.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-306 Missing Authentication for Critical Function1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2022-25620No exploit | Stored Cross-Site Scripting (XSS)profelis · sambabox · CWE-80 | Critical9.0 | — | 0.4% | Mar 30, 2022 |
28Monitor | CVE-2024-7015No exploit | Improper Authentication in Profelis Informatics and Consulting's PassBOXprofelis · passbox · CWE-306 | High7.1 | — | 0.4% | Sep 9, 2024 |
26Monitor | CVE-2022-25619No exploit | Authenticated Command Injection to RCEprofelis · sambabox · CWE-77 | Medium6.7 | — | 0.3% | Mar 30, 2022 |
- CVE-2022-2562036Monitor
Stored Cross-Site Scripting (XSS)
CriticalCVSS 9.0No exploitEPSS 0%profelis · sambaboxMar 30, 2022
- CVE-2024-701528Monitor
Improper Authentication in Profelis Informatics and Consulting's PassBOX
HighCVSS 7.1No exploitEPSS 0%profelis · passboxSep 9, 2024
- CVE-2022-2561926Monitor
Authenticated Command Injection to RCE
MediumCVSS 6.7No exploitEPSS 0%profelis · sambaboxMar 30, 2022