sickrage records
3 published records for vendor sickrage.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 33.3%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-522 Insufficiently Protected Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2018-9160Weaponized | SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.sickrage · sickrage · CWE-522 | Critical9.8 | — | 75.6% | Mar 31, 2018 |
24Monitor | CVE-2021-25926No exploit | In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validatsickrage · sickrage · CWE-79 | Medium6.1 | — | 0.8% | Apr 12, 2021 |
21Monitor | CVE-2021-25925No exploit | in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated propersickrage · sickrage · CWE-79 | Medium5.4 | — | 0.7% | Apr 12, 2021 |
- CVE-2018-916062This week
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
CriticalCVSS 9.8WeaponizedEPSS 76%sickrage · sickrageMar 31, 2018
- CVE-2021-2592624Monitor
In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validat
MediumCVSS 6.1No exploitEPSS 1%sickrage · sickrageApr 12, 2021
- CVE-2021-2592521Monitor
in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated proper
MediumCVSS 5.4No exploitEPSS 1%sickrage · sickrageApr 12, 2021