smartstore records
7 published records for vendor smartstore.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2021-32608No exploit | An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1.smartstore · smartstore | Critical9.8 | — | 33.4% | May 12, 2021 |
49Plan | CVE-2021-32607No exploit | An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1.smartstore · smartstore | Critical9.8 | — | 33.4% | May 12, 2021 |
39Monitor | CVE-2020-15243No exploit | WebApi Authentication attribute missing in Smartstoresmartstore · smartstore · CWE-287 | Critical9.8 | — | 1.2% | Oct 8, 2020 |
37Monitor | CVE-2020-36364No exploit | An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0.smartstore · smartstorenet · CWE-22 | Critical9.1 | — | 1.8% | May 19, 2021 |
36Monitor | CVE-2020-27996No exploit | An issue was discovered in SmartStoreNET before 4.0.1.smartstore · smartstorenet | High8.8 | — | 2.2% | Oct 29, 2020 |
35Monitor | CVE-2020-27997No exploit | An issue was discovered in SmartStoreNET before 4.1.0.smartstore · smartstorenet · CWE-352 | High8.8 | — | 0.8% | Feb 19, 2021 |
25Monitor | CVE-2020-36365Proof of concept | Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskContsmartstore · smartstorenet · CWE-601 | Medium6.1 | — | 3.0% | May 19, 2021 |
- CVE-2021-3260849Plan
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1.
CriticalCVSS 9.8No exploitEPSS 33%smartstore · smartstoreMay 12, 2021
- CVE-2021-3260749Plan
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1.
CriticalCVSS 9.8No exploitEPSS 33%smartstore · smartstoreMay 12, 2021
- CVE-2020-1524339Monitor
WebApi Authentication attribute missing in Smartstore
CriticalCVSS 9.8No exploitEPSS 1%smartstore · smartstoreOct 8, 2020
- CVE-2020-3636437Monitor
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0.
CriticalCVSS 9.1No exploitEPSS 2%smartstore · smartstorenetMay 19, 2021
- CVE-2020-2799636Monitor
An issue was discovered in SmartStoreNET before 4.0.1.
HighCVSS 8.8No exploitEPSS 2%smartstore · smartstorenetOct 29, 2020
- CVE-2020-2799735Monitor
An issue was discovered in SmartStoreNET before 4.1.0.
HighCVSS 8.8No exploitEPSS 1%smartstore · smartstorenetFeb 19, 2021
- CVE-2020-3636525Monitor
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskCont
MediumCVSS 6.1Proof of conceptEPSS 3%smartstore · smartstorenetMay 19, 2021