Записи filecloud
7 опубликованных записей вендора filecloud.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 14,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-284 Improper Access Control1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2022-25241Proof of concept | In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).filecloud · filecloud · CWE-352 | Высокая8,8 | — | 3,3 % | 15 февр. 2022 г. |
35Наблюдать | CVE-2016-6578Эксплойта нет | CodeLathe FileCloud, version 13.0.0.32841 and earlier, is vulnerable to cross-site request forgery (CSRF)filecloud · filecloud · CWE-352 | Высокая8,8 | — | 0,9 % | 13 июл. 2018 г. |
35Наблюдать | CVE-2022-25242Эксплойта нет | In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).filecloud · filecloud · CWE-352 | Высокая8,8 | — | 0,4 % | 15 февр. 2022 г. |
29Наблюдать | CVE-2022-39833Эксплойта нет | FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported APIfilecloud · filecloud · CWE-94 | Высокая7,2 | — | 2,8 % | 23 нояб. 2022 г. |
26Наблюдать | CVE-2022-1958Эксплойта нет | FileCloud NTFS access controlfilecloud · filecloud · CWE-284 | Средняя6,5 | — | 0,7 % | 15 июн. 2022 г. |
21Наблюдать | CVE-2020-26524Эксплойта нет | CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.filecloud · filecloud | Средняя5,3 | — | 1,4 % | 2 окт. 2020 г. |
21Наблюдать | CVE-2022-24633Эксплойта нет | All versions of FileCloud prior to 21.3 are vulnerable to user enumeration.filecloud · filecloud · CWE-200 | Средняя5,3 | — | 0,8 % | 24 февр. 2022 г. |
- CVE-2022-2524136Наблюдать
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %filecloud · filecloud15 февр. 2022 г.
- CVE-2016-657835Наблюдать
CodeLathe FileCloud, version 13.0.0.32841 and earlier, is vulnerable to cross-site request forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %filecloud · filecloud13 июл. 2018 г.
- CVE-2022-2524235Наблюдать
In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %filecloud · filecloud15 февр. 2022 г.
- CVE-2022-3983329Наблюдать
FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %filecloud · filecloud23 нояб. 2022 г.
- CVE-2022-195826Наблюдать
FileCloud NTFS access control
СредняяCVSS 6,5Эксплойта нетEPSS 1 %filecloud · filecloud15 июн. 2022 г.
- CVE-2020-2652421Наблюдать
CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %filecloud · filecloud2 окт. 2020 г.
- CVE-2022-2463321Наблюдать
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %filecloud · filecloud24 февр. 2022 г.