snapt records
3 published records for vendor snapt.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2022-24237No exploit | The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability.snapt · aria · CWE-78 | High8.8 | — | 25.3% | Mar 21, 2022 |
35Monitor | CVE-2022-24235No exploit | A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrasnapt · aria · CWE-352 | High8.8 | — | 0.7% | Mar 21, 2022 |
14Monitor | CVE-2022-24236No exploit | An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed users' accounts.snapt · aria · CWE-732 | Low3.5 | — | 0.6% | Mar 21, 2022 |
- CVE-2022-2423743Plan
The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability.
HighCVSS 8.8No exploitEPSS 25%snapt · ariaMar 21, 2022
- CVE-2022-2423535Monitor
A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitra
HighCVSS 8.8No exploitEPSS 1%snapt · ariaMar 21, 2022
- CVE-2022-2423614Monitor
An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed users' accounts.
LowCVSS 3.5No exploitEPSS 1%snapt · ariaMar 21, 2022