Перейти к содержимому
Noroxi

Записи Creativeitem

26 опубликованных записей вендора creativeitem.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

26 записей
  • CVE-2023-4974
    41В плане

    Academy LMS GET Parameter filter sql injection

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    creativeitem · academy lms14 сент. 2023 г.

  • CVE-2025-56749
    37Наблюдать

    Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing.

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    creativeitem · academy lms15 окт. 2025 г.

  • CVE-2022-47132
    35Наблюдать

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.

    ВысокаяCVSS 8,8Proof of conceptEPSS 1 %

    creativeitem · academy lms2 февр. 2023 г.

  • CVE-2020-22273
    26Наблюдать

    Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Setting

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    creativeitem · neoflex video subscription system4 нояб. 2020 г.

  • CVE-2025-56747
    26Наблюдать

    Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regul

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    creativeitem · academy lms14 окт. 2025 г.

  • CVE-2023-4119
    25Наблюдать

    Academy LMS courses cross site scripting

    СредняяCVSS 6,1Proof of conceptEPSS 4 %

    creativeitem · academy lms3 авг. 2023 г.

  • CVE-2022-38553
    25Наблюдать

    Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Sear

    СредняяCVSS 6,1Proof of conceptEPSS 3 %

    creativeitem · academy learning management system26 сент. 2022 г.

  • CVE-2023-4973
    25Наблюдать

    Academy LMS GET Parameter filter cross site scripting

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    creativeitem · academy lms14 сент. 2023 г.

  • CVE-2025-56748
    25Наблюдать

    Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limi

    СредняяCVSS 6,4Эксплойта нетEPSS 0 %

    creativeitem · academy lms15 окт. 2025 г.

  • CVE-2023-38964
    24Наблюдать

    Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    creativeitem · academy lms4 авг. 2023 г.

  • CVE-2024-38959
    24Наблюдать

    Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attacker to execute arbitr

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    creativeitem · academy lms9 июл. 2024 г.

  • CVE-2023-3754
    24Наблюдать

    Creativeitem Ekushey Project Manager CRM xxxxxxxx[random-msg-hash] cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    creativeitem · ekushey project manager18 июл. 2023 г.

  • CVE-2023-3756
    24Наблюдать

    Creativeitem Atlas Business Directory Listing search cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    creativeitem · atlas19 июл. 2023 г.

  • CVE-2023-3755
    24Наблюдать

    Creativeitem Atlas Business Directory Listing filter_listings cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    creativeitem · atlas19 июл. 2023 г.

  • CVE-2023-3753
    24Наблюдать

    Creativeitem Mastery LMS browse cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    creativeitem · mastery lms18 июл. 2023 г.

  • CVE-2023-3752
    24Наблюдать

    Creativeitem Academy LMS courses cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    creativeitem · academy lms18 июл. 2023 г.

  • CVE-2025-71179
    24Наблюдать

    Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs en

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    creativeitem · academy lms3 февр. 2026 г.

  • CVE-2018-18417
    21Наблюдать

    In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the n

    СредняяCVSS 5,4Proof of conceptEPSS 2 %

    creativeitem · ekushey project manager19 окт. 2018 г.

  • CVE-2023-53876
    20Наблюдать

    Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    creativeitem · academy lms15 дек. 2025 г.

  • CVE-2025-40991
    20Наблюдать

    Stored XSS in Creativeitem Ekushey CRM

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    creativeitem · ekushey project manager crm2 окт. 2025 г.

  • CVE-2025-40989
    20Наблюдать

    Stored XSS in Creativeitem Ekushey CRM

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    creativeitem · ekushey project manager crm2 окт. 2025 г.

  • CVE-2025-40990
    20Наблюдать

    Stored XSS in Creativeitem Ekushey CRM

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    creativeitem · ekushey project manager crm2 окт. 2025 г.

  • CVE-2022-29380
    19Наблюдать

    Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.

    СредняяCVSS 4,8Proof of conceptEPSS 1 %

    creativeitem · academy lms25 мая 2022 г.

  • CVE-2022-47131
    19Наблюдать

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.

    СредняяCVSS 4,8Proof of conceptEPSS 0 %

    creativeitem · academy lms2 февр. 2023 г.

  • CVE-2022-47130
    17Наблюдать

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with admin

    СредняяCVSS 4,3Proof of conceptEPSS 1 %

    creativeitem · academy lms2 февр. 2023 г.