thycotic records
9 published records for vendor thycotic.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-255 Credentials Management Errors1
- CWE-295 Improper Certificate Validation1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2019-18355No exploit | An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.thycotic · secret server · CWE-918 | Critical9.8 | — | 1.5% | Oct 23, 2019 |
39Monitor | CVE-2014-4861No exploit | The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encryptethycotic · secret server · CWE-255 | Critical9.8 | — | 1.2% | Mar 9, 2018 |
30Monitor | CVE-2021-34679No exploit | Thycotic Password Reset Server before 5.3.0 allows credential disclosure.thycotic · password reset server | High7.5 | — | 1.0% | Jun 11, 2021 |
26Monitor | CVE-2021-41845No exploit | A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007.thycotic · secret server · CWE-89 | Medium6.5 | — | 0.7% | Oct 1, 2021 |
24Monitor | CVE-2019-18356No exploit | An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2).thycotic · secret server · CWE-79 | Medium6.1 | — | 0.8% | Oct 23, 2019 |
24Monitor | CVE-2019-18357No exploit | An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2).thycotic · secret server · CWE-79 | Medium6.1 | — | 0.8% | Oct 23, 2019 |
23Monitor | CVE-2015-4094No exploit | The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allowthycotic · secret server · CWE-295 | Medium5.8 | — | 0.6% | Jun 2, 2015 |
21Monitor | CVE-2017-11725No exploit | The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.thycotic · secret server · CWE-601 | Medium5.4 | — | 0.6% | Jul 29, 2017 |
15Monitor | CVE-2015-3443Proof of concept | Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before 8.8.000005 allows rthycotic · secret server · CWE-79 | Low3.5 | — | 2.0% | Jul 2, 2015 |
- CVE-2019-1835539Monitor
An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.
CriticalCVSS 9.8No exploitEPSS 2%thycotic · secret serverOct 23, 2019
- CVE-2014-486139Monitor
The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encrypte
CriticalCVSS 9.8No exploitEPSS 1%thycotic · secret serverMar 9, 2018
- CVE-2021-3467930Monitor
Thycotic Password Reset Server before 5.3.0 allows credential disclosure.
HighCVSS 7.5No exploitEPSS 1%thycotic · password reset serverJun 11, 2021
- CVE-2021-4184526Monitor
A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007.
MediumCVSS 6.5No exploitEPSS 1%thycotic · secret serverOct 1, 2021
- CVE-2019-1835624Monitor
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2).
MediumCVSS 6.1No exploitEPSS 1%thycotic · secret serverOct 23, 2019
- CVE-2019-1835724Monitor
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2).
MediumCVSS 6.1No exploitEPSS 1%thycotic · secret serverOct 23, 2019
- CVE-2015-409423Monitor
The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allow
MediumCVSS 5.8No exploitEPSS 1%thycotic · secret serverJun 2, 2015
- CVE-2017-1172521Monitor
The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.
MediumCVSS 5.4No exploitEPSS 1%thycotic · secret serverJul 29, 2017
- CVE-2015-344315Monitor
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before 8.8.000005 allows r
LowCVSS 3.5Proof of conceptEPSS 2%thycotic · secret serverJul 2, 2015