Записи Alinto
16 опубликованных записей вендора alinto.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-707 Improper Neutralization2
- CWE-184 Incomplete List of Disallowed Inputs1
- CWE-308 Use of Single-factor Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-399 Resource Management Errors1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2015-5395Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.debian · debian linux · CWE-352 | Высокая8,8 | — | 0,9 % | 20 сент. 2017 г. |
27Наблюдать | CVE-2016-6188Эксплойта нет | Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to uploadalinto · sogo · CWE-399 | Средняя6,5 | — | 2,2 % | 3 февр. 2017 г. |
24Наблюдать | CVE-2014-9905Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web alinto · sogo · CWE-79 | Средняя6,1 | — | 1,2 % | 17 февр. 2017 г. |
24Наблюдать | CVE-2016-6191Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackalinto · sogo · CWE-79 | Средняя6,1 | — | 1,2 % | 17 февр. 2017 г. |
24Наблюдать | CVE-2023-48104Proof of concept | Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.alinto · sogo · CWE-79 | Средняя6,1 | — | 1,0 % | 15 янв. 2024 г. |
24Наблюдать | CVE-2022-4556Proof of concept | Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scriptingalinto · sogo · CWE-707 | Средняя6,1 | — | 0,6 % | 16 дек. 2022 г. |
24Наблюдать | CVE-2022-4558Эксплойта нет | Alinto SOGo Folder/Mail NSString+Utilities.m cross site scriptingalinto · sogo · CWE-707 | Средняя6,1 | — | 0,6 % | 16 дек. 2022 г. |
24Наблюдать | CVE-2024-24510Эксплойта нет | Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function talinto · sogo · CWE-79 | Средняя6,1 | — | 0,5 % | 9 сент. 2024 г. |
24Наблюдать | CVE-2020-22402Эксплойта нет | Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reaalinto · sogo web mail · CWE-79 | Средняя6,1 | — | 0,4 % | 14 июн. 2023 г. |
24Наблюдать | CVE-2024-34462Эксплойта нет | Alinto SOGo through 5.10.0 allows XSS during attachment preview.alinto · sogo · CWE-79 | Средняя6,1 | — | 0,3 % | 4 мая 2024 г. |
24Наблюдать | CVE-2025-63499Proof of concept | Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.alinto · sogo · CWE-79 | Средняя6,1 | — | 0,3 % | 4 дек. 2025 г. |
24Наблюдать | CVE-2025-63498Proof of concept | alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.alinto · sogo · CWE-79 | Средняя6,1 | — | 0,3 % | 24 нояб. 2025 г. |
24Наблюдать | CVE-2025-71276Эксплойта нет | SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.alinto · sogo · CWE-79 | Средняя6,1 | — | 0,1 % | 21 мар. 2026 г. |
17Наблюдать | CVE-2016-6189Эксплойта нет | Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by readingalinto · sogo · CWE-184 | Средняя4,3 | — | 1,4 % | 17 февр. 2017 г. |
10Наблюдать | CVE-2026-33550Эксплойта нет | SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommalinto · sogo · CWE-308 | Низкая2,6 | — | 0,2 % | 21 мар. 2026 г. |
8Наблюдать | CVE-2026-3054Эксплойта нет | Alinto SOGo cross site scriptingalinto · sogo · CWE-79 | Низкая2,1 | — | 0,5 % | 23 февр. 2026 г. |
- CVE-2015-539535Наблюдать
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %debian · debian linux20 сент. 2017 г.
- CVE-2016-618827Наблюдать
Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload
СредняяCVSS 6,5Эксплойта нетEPSS 2 %alinto · sogo3 февр. 2017 г.
- CVE-2014-990524Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web
СредняяCVSS 6,1Эксплойта нетEPSS 1 %alinto · sogo17 февр. 2017 г.
- CVE-2016-619124Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attack
СредняяCVSS 6,1Эксплойта нетEPSS 1 %alinto · sogo17 февр. 2017 г.
- CVE-2023-4810424Наблюдать
Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.
СредняяCVSS 6,1Proof of conceptEPSS 1 %alinto · sogo15 янв. 2024 г.
- CVE-2022-455624Наблюдать
Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scripting
СредняяCVSS 6,1Proof of conceptEPSS 1 %alinto · sogo16 дек. 2022 г.
- CVE-2022-455824Наблюдать
Alinto SOGo Folder/Mail NSString+Utilities.m cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %alinto · sogo16 дек. 2022 г.
- CVE-2024-2451024Наблюдать
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function t
СредняяCVSS 6,1Эксплойта нетEPSS 0 %alinto · sogo9 сент. 2024 г.
- CVE-2020-2240224Наблюдать
Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user rea
СредняяCVSS 6,1Эксплойта нетEPSS 0 %alinto · sogo web mail14 июн. 2023 г.
- CVE-2024-3446224Наблюдать
Alinto SOGo through 5.10.0 allows XSS during attachment preview.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %alinto · sogo4 мая 2024 г.
- CVE-2025-6349924Наблюдать
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
СредняяCVSS 6,1Proof of conceptEPSS 0 %alinto · sogo4 дек. 2025 г.
- CVE-2025-6349824Наблюдать
alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
СредняяCVSS 6,1Proof of conceptEPSS 0 %alinto · sogo24 нояб. 2025 г.
- CVE-2025-7127624Наблюдать
SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %alinto · sogo21 мар. 2026 г.
- CVE-2016-618917Наблюдать
Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading
СредняяCVSS 4,3Эксплойта нетEPSS 1 %alinto · sogo17 февр. 2017 г.
- CVE-2026-3355010Наблюдать
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recomm
НизкаяCVSS 2,6Эксплойта нетEPSS 0 %alinto · sogo21 мар. 2026 г.
- CVE-2026-30548Наблюдать
Alinto SOGo cross site scripting
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %alinto · sogo23 февр. 2026 г.