squaredup records
13 published records for vendor squaredup.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-203 Observable Discrepancy1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-40091No exploit | An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.squaredup · squaredup · CWE-918 | Critical9.8 | — | 1.1% | Dec 6, 2021 |
26Monitor | CVE-2020-9388No exploit | CSRF protection was not present in SquaredUp before version 4.6.0.squaredup · squaredup · CWE-352 | Medium6.5 | — | 0.8% | Feb 3, 2021 |
24Monitor | CVE-2022-46785No exploit | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).squaredup · dashboard server · CWE-79 | Medium6.1 | — | 0.4% | Feb 23, 2023 |
24Monitor | CVE-2022-46784No exploit | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection.squaredup · dashboard server · CWE-601 | Medium6.1 | — | 0.4% | Feb 23, 2023 |
21Monitor | CVE-2020-9390No exploit | SquaredUp allowed Stored XSS before version 4.6.0.squaredup · squaredup · CWE-79 | Medium5.4 | — | 0.9% | Feb 3, 2021 |
21Monitor | CVE-2021-40096No exploit | A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject asquaredup · squaredup · CWE-79 | Medium5.4 | — | 0.7% | Dec 7, 2021 |
21Monitor | CVE-2021-40093No exploit | A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject asquaredup · squaredup · CWE-79 | Medium5.4 | — | 0.6% | Dec 7, 2021 |
21Monitor | CVE-2021-40092No exploit | A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web scsquaredup · squaredup · CWE-79 | Medium5.4 | — | 0.6% | Dec 7, 2021 |
21Monitor | CVE-2021-40094No exploit | A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654.squaredup · squaredup · CWE-79 | Medium5.4 | — | 0.5% | Dec 7, 2021 |
21Monitor | CVE-2022-46786No exploit | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2).squaredup · dashboard server · CWE-79 | Medium5.4 | — | 0.4% | Feb 23, 2023 |
21Monitor | CVE-2024-45180No exploit | SquaredUp DS for SCOM 6.2.1.11104 allows XSS.squaredup · squaredup ds for scom · CWE-79 | Medium5.4 | — | 0.2% | Sep 3, 2024 |
19Monitor | CVE-2021-40095No exploit | An issue was discovered in SquaredUp for SCOM 5.2.1.6654.squaredup · squaredup | Medium4.9 | — | 1.0% | Dec 7, 2021 |
14Monitor | CVE-2020-9389No exploit | A username enumeration issue was discovered in SquaredUp before version 4.6.0.squaredup · squaredup · CWE-203 | Low3.7 | — | 0.9% | Feb 3, 2021 |
- CVE-2021-4009139Monitor
An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.
CriticalCVSS 9.8No exploitEPSS 1%squaredup · squaredupDec 6, 2021
- CVE-2020-938826Monitor
CSRF protection was not present in SquaredUp before version 4.6.0.
MediumCVSS 6.5No exploitEPSS 1%squaredup · squaredupFeb 3, 2021
- CVE-2022-4678524Monitor
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).
MediumCVSS 6.1No exploitEPSS 0%squaredup · dashboard serverFeb 23, 2023
- CVE-2022-4678424Monitor
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection.
MediumCVSS 6.1No exploitEPSS 0%squaredup · dashboard serverFeb 23, 2023
- CVE-2020-939021Monitor
SquaredUp allowed Stored XSS before version 4.6.0.
MediumCVSS 5.4No exploitEPSS 1%squaredup · squaredupFeb 3, 2021
- CVE-2021-4009621Monitor
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject a
MediumCVSS 5.4No exploitEPSS 1%squaredup · squaredupDec 7, 2021
- CVE-2021-4009321Monitor
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject a
MediumCVSS 5.4No exploitEPSS 1%squaredup · squaredupDec 7, 2021
- CVE-2021-4009221Monitor
A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web sc
MediumCVSS 5.4No exploitEPSS 1%squaredup · squaredupDec 7, 2021
- CVE-2021-4009421Monitor
A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654.
MediumCVSS 5.4No exploitEPSS 0%squaredup · squaredupDec 7, 2021
- CVE-2022-4678621Monitor
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2).
MediumCVSS 5.4No exploitEPSS 0%squaredup · dashboard serverFeb 23, 2023
- CVE-2024-4518021Monitor
SquaredUp DS for SCOM 6.2.1.11104 allows XSS.
MediumCVSS 5.4No exploitEPSS 0%squaredup · squaredup ds for scomSep 3, 2024
- CVE-2021-4009519Monitor
An issue was discovered in SquaredUp for SCOM 5.2.1.6654.
MediumCVSS 4.9No exploitEPSS 1%squaredup · squaredupDec 7, 2021
- CVE-2020-938914Monitor
A username enumeration issue was discovered in SquaredUp before version 4.6.0.
LowCVSS 3.7No exploitEPSS 1%squaredup · squaredupFeb 3, 2021