Записи Delinea
13 опубликованных записей вендора delinea.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-26 Path Traversal: '/dir/../filename'2
- CWE-287 Improper Authentication2
- CWE-284 Improper Access Control1
- CWE-316 Cleartext Storage of Sensitive Information in Memory1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-321 Use of Hard-coded Cryptographic Key1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2024-33891Эксплойта нет | Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebServicedelinea · secret server · CWE-321 | Высокая8,8 | — | 1,0 % | 28 апр. 2024 г. |
33Наблюдать | CVE-2024-12908Эксплойта нет | Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the protocol handler function,delinea · secret server · CWE-94 | Высокая8,3 | — | 0,7 % | 26 дек. 2024 г. |
33Наблюдать | CVE-2024-25652Эксплойта нет | In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionadelinea · secret server · CWE-287 | Высокая8,4 | — | 0,6 % | 13 мар. 2024 г. |
28Наблюдать | CVE-2023-4589Эксплойта нет | Insufficient verification of data authenticity vulnerability in Delinea Secret Serverdelinea · secret server · CWE-345 | Высокая7,2 | — | 0,3 % | 6 сент. 2023 г. |
26Наблюдать | CVE-2024-5865Эксплойта нет | Arbitrary File Reading in Centrify PASdelinea · privileged access service · CWE-26 | Средняя6,5 | — | 0,5 % | 2 июл. 2024 г. |
26Наблюдать | CVE-2024-25649Эксплойта нет | In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the follodelinea · secret server · CWE-316 | Средняя6,7 | — | 0,1 % | 13 мар. 2024 г. |
23Наблюдать | CVE-2024-25650Эксплойта нет | Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmedelinea · distributed engine · CWE-319 | Средняя5,9 | — | 0,3 % | 13 мар. 2024 г. |
21Наблюдать | CVE-2024-25651Эксплойта нет | User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4.delinea · secret server · CWE-203 | Средняя5,3 | — | 0,5 % | 13 мар. 2024 г. |
21Наблюдать | CVE-2025-12810Эксплойта нет | Failure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of Credentialsdelinea · secret server · CWE-287 | Средняя5,3 | — | 0,5 % | 27 янв. 2026 г. |
19Наблюдать | CVE-2023-4588Эксплойта нет | File accessibility vulnerability in Delinea Secret Serverdelinea · secret server · CWE-552 | Средняя4,9 | — | 0,3 % | 6 сент. 2023 г. |
17Наблюдать | CVE-2024-25653Эксплойта нет | Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is delinea · secret server · CWE-284 | Средняя4,3 | — | 0,4 % | 13 мар. 2024 г. |
17Наблюдать | CVE-2024-5866Эксплойта нет | Arbitrary Directory Listing in Centrify PASdelinea · privileged access service · CWE-26 | Средняя4,3 | — | 0,4 % | 2 июл. 2024 г. |
16Наблюдать | CVE-2025-6943Эксплойта нет | Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to rdelinea · secret server · CWE-269 | Средняя4,0 | — | 0,2 % | 2 июл. 2025 г. |
- CVE-2024-3389135Наблюдать
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %delinea · secret server28 апр. 2024 г.
- CVE-2024-1290833Наблюдать
Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the protocol handler function,
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %delinea · secret server26 дек. 2024 г.
- CVE-2024-2565233Наблюдать
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functiona
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %delinea · secret server13 мар. 2024 г.
- CVE-2023-458928Наблюдать
Insufficient verification of data authenticity vulnerability in Delinea Secret Server
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %delinea · secret server6 сент. 2023 г.
- CVE-2024-586526Наблюдать
Arbitrary File Reading in Centrify PAS
СредняяCVSS 6,5Эксплойта нетEPSS 0 %delinea · privileged access service2 июл. 2024 г.
- CVE-2024-2564926Наблюдать
In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the follo
СредняяCVSS 6,7Эксплойта нетEPSS 0 %delinea · secret server13 мар. 2024 г.
- CVE-2024-2565023Наблюдать
Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symme
СредняяCVSS 5,9Эксплойта нетEPSS 0 %delinea · distributed engine13 мар. 2024 г.
- CVE-2024-2565121Наблюдать
User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %delinea · secret server13 мар. 2024 г.
- CVE-2025-1281021Наблюдать
Failure in Password Rotation and Check-in Mechanism in Secret Server Allows Reuse of Credentials
СредняяCVSS 5,3Эксплойта нетEPSS 0 %delinea · secret server27 янв. 2026 г.
- CVE-2023-458819Наблюдать
File accessibility vulnerability in Delinea Secret Server
СредняяCVSS 4,9Эксплойта нетEPSS 0 %delinea · secret server6 сент. 2023 г.
- CVE-2024-2565317Наблюдать
Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is
СредняяCVSS 4,3Эксплойта нетEPSS 0 %delinea · secret server13 мар. 2024 г.
- CVE-2024-586617Наблюдать
Arbitrary Directory Listing in Centrify PAS
СредняяCVSS 4,3Эксплойта нетEPSS 0 %delinea · privileged access service2 июл. 2024 г.
- CVE-2025-694316Наблюдать
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to r
СредняяCVSS 4,0Эксплойта нетEPSS 0 %delinea · secret server2 июл. 2025 г.