red-gate records
6 published records for vendor red-gate.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-20 Improper Input Validation1
- CWE-284 Improper Access Control1
- CWE-295 Improper Certificate Validation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2015-9098Proof of concept | In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in tred-gate · sql monitor · CWE-89 | Critical9.8 | — | 14.1% | Jun 22, 2017 |
35Monitor | CVE-2022-47542No exploit | Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.red-gate · sql monitor · CWE-284 | High8.8 | — | 0.6% | Mar 30, 2023 |
32Monitor | CVE-2018-14581No exploit | Redgate .NET Reflector before 10.0.7.774 and SmartAssembly before 6.12.5 allow attackers to execute code by decompiling a compiled .NET objered-gate · .net reflector · CWE-20 | High7.8 | — | 1.8% | Jul 31, 2018 |
28Monitor | CVE-2020-9318No exploit | Red Gate SQL Monitor 9.0.13 through 9.2.14 allows an administrative user to perform a SQL injection attack by configuring the SNMP alert setred-gate · sql monitor · CWE-89 | High7.2 | — | 0.9% | Feb 20, 2020 |
25Monitor | CVE-2022-47870Proof of concept | A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to ired-gate · sql monitor · CWE-79 | Medium6.1 | — | 2.2% | Apr 4, 2023 |
23Monitor | CVE-2020-15526No exploit | In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond thatred-gate · sql monitor · CWE-295 | Medium5.9 | — | 0.5% | Jul 9, 2020 |
- CVE-2015-909843Plan
In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in t
CriticalCVSS 9.8Proof of conceptEPSS 14%red-gate · sql monitorJun 22, 2017
- CVE-2022-4754235Monitor
Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.
HighCVSS 8.8No exploitEPSS 1%red-gate · sql monitorMar 30, 2023
- CVE-2018-1458132Monitor
Redgate .NET Reflector before 10.0.7.774 and SmartAssembly before 6.12.5 allow attackers to execute code by decompiling a compiled .NET obje
HighCVSS 7.8No exploitEPSS 2%red-gate · .net reflectorJul 31, 2018
- CVE-2020-931828Monitor
Red Gate SQL Monitor 9.0.13 through 9.2.14 allows an administrative user to perform a SQL injection attack by configuring the SNMP alert set
HighCVSS 7.2No exploitEPSS 1%red-gate · sql monitorFeb 20, 2020
- CVE-2022-4787025Monitor
A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to i
MediumCVSS 6.1Proof of conceptEPSS 2%red-gate · sql monitorApr 4, 2023
- CVE-2020-1552623Monitor
In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond that
MediumCVSS 5.9No exploitEPSS 0%red-gate · sql monitorJul 9, 2020