Перейти к содержимому
Noroxi

Записи eramba

11 опубликованных записей вендора eramba.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 9,1 %
Pre-auth RCE
0
С записью об исправлении
9,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 18
  2. 20
  3. 22
  4. 23
  5. 24
  6. 26

Столбик: всего · тёмная часть: CISA KEV.

Все записи

11 записей
  • CVE-2023-36255
    51В плане

    An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 53 %

    eramba · eramba2 авг. 2023 г.

  • CVE-2020-25105
    39Наблюдать

    eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    eramba · eramba3 сент. 2020 г.

  • CVE-2025-55462
    26Наблюдать

    A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in t

    СредняяCVSS 6,5Proof of conceptEPSS 0 %

    eramba · eramba13 янв. 2026 г.

  • CVE-2018-7894
    24Наблюдать

    Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter)

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    eramba · eramba9 мар. 2018 г.

  • CVE-2018-7741
    24Наблюдать

    Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    eramba · eramba7 мар. 2018 г.

  • CVE-2018-7996
    24Наблюдать

    Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    eramba · eramba9 мар. 2018 г.

  • CVE-2018-7997
    24Наблюдать

    Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV file polluted

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    eramba · eramba9 мар. 2018 г.

  • CVE-2020-25104
    21Наблюдать

    eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    eramba · eramba3 сент. 2020 г.

  • CVE-2022-43342
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary we

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    eramba · eramba14 нояб. 2022 г.

  • CVE-2024-27593
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated att

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    15 мая 2024 г.

  • CVE-2020-28031
    17Наблюдать

    eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    eramba · eramba2 нояб. 2020 г.