StrangeBee records
5 published records for vendor strangebee.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-306 Missing Authentication for Critical Function1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-39069No exploit | An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentstrangebee · cortex · CWE-287 | Critical9.8 | — | 0.9% | Sep 11, 2023 |
36Monitor | CVE-2017-18376No exploit | An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write accestrangebee · thehive · CWE-264 | High8.8 | — | 1.9% | Jun 2, 2019 |
27Monitor | CVE-2026-63098No exploit | TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpointstrangebee · thehive · CWE-306 | Medium6.9 | — | 0.4% | Jul 17, 2026 |
21Monitor | CVE-2024-22876No exploit | StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which strangebee · thehive · CWE-79 | Medium5.4 | — | 0.3% | Jan 19, 2024 |
21Monitor | CVE-2024-22877No exploit | StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality.strangebee · thehive · CWE-79 | Medium5.4 | — | 0.3% | Jan 19, 2024 |
- CVE-2023-3906939Monitor
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authent
CriticalCVSS 9.8No exploitEPSS 1%strangebee · cortexSep 11, 2023
- CVE-2017-1837636Monitor
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write acce
HighCVSS 8.8No exploitEPSS 2%strangebee · thehiveJun 2, 2019
- CVE-2026-6309827Monitor
TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
MediumCVSS 6.9No exploitEPSS 0%strangebee · thehiveJul 17, 2026
- CVE-2024-2287621Monitor
StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which
MediumCVSS 5.4No exploitEPSS 0%strangebee · thehiveJan 19, 2024
- CVE-2024-2287721Monitor
StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality.
MediumCVSS 5.4No exploitEPSS 0%strangebee · thehiveJan 19, 2024