Перейти к содержимому
Noroxi

Записи etherpad

19 опубликованных записей вендора etherpad.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
10,5 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

19 записей
  • CVE-2018-9845
    43В плане

    Etherpad Lite before 1.6.4 is exploitable for admin access.

    КритическаяCVSS 9,8Proof of conceptEPSS 13 %

    etherpad · etherpad lite29 апр. 2018 г.

  • CVE-2018-6835
    40В плане

    node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access rest

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    etherpad · etherpad8 февр. 2018 г.

  • CVE-2018-9326
    40В плане

    Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    etherpad · etherpad7 апр. 2018 г.

  • CVE-2021-43802
    36Наблюдать

    Admin privilege escalation and arbitrary code execution via malicious *.etherpad imports

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    etherpad · etherpad9 дек. 2021 г.

  • CVE-2018-9327
    32Наблюдать

    Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %

    etherpad · etherpad7 апр. 2018 г.

  • CVE-2015-3297
    31Наблюдать

    Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by

    ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %

    etherpad · etherpad7 июл. 2017 г.

  • CVE-2015-2298
    31Наблюдать

    node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an im

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    etherpad · etherpad12 янв. 2018 г.

  • CVE-2015-4085
    31Наблюдать

    Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    etherpad · etherpad7 сент. 2017 г.

  • CVE-2015-3309
    31Наблюдать

    Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files wi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    etherpad · etherpad13 февр. 2020 г.

  • CVE-2018-9325
    30Наблюдать

    Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    etherpad · etherpad7 апр. 2018 г.

  • CVE-2020-22781
    30Наблюдать

    In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    etherpad · etherpad28 апр. 2021 г.

  • CVE-2020-22782
    30Наблюдать

    Etherpad < 1.8.3 is affected by a denial of service in the import functionality.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    etherpad · etherpad28 апр. 2021 г.

  • CVE-2020-22785
    30Наблюдать

    Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    etherpad · etherpad28 апр. 2021 г.

  • CVE-2020-22784
    30Наблюдать

    In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    etherpad · ueberdb28 апр. 2021 г.

  • CVE-2021-34816
    29Наблюдать

    An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by i

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    etherpad · etherpad21 июл. 2021 г.

  • CVE-2020-22783
    26Наблюдать

    Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    etherpad · etherpad28 апр. 2021 г.

  • CVE-2021-34817
    24Наблюдать

    A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML b

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    etherpad · etherpad19 июл. 2021 г.

  • CVE-2018-6834
    24Наблюдать

    static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    etherpad · etherpad lite8 февр. 2018 г.

  • CVE-2019-18209
    24Наблюдать

    templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    etherpad · etherpad18 окт. 2019 г.