Записи galaxyproject
7 опубликованных записей вендора galaxyproject.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 42,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-284 Improper Access Control1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2015-10062Эксплойта нет | galaxy-data-resource Command Line Template injectiongalaxyproject · galaxy · CWE-74 | Критическая9,8 | — | 0,9 % | 17 янв. 2023 г. |
36Наблюдать | CVE-2024-42351Эксплойта нет | Possible Data Tampering & Loss of Public Datasets in Galaxygalaxyproject · galaxy · CWE-200 | Критическая9,1 | — | 0,5 % | 20 сент. 2024 г. |
30Наблюдать | CVE-2022-23470Эксплойта нет | Arbitrary file access in the Galaxy data analysis platformgalaxyproject · galaxy · CWE-22 | Высокая7,5 | — | 0,8 % | 6 дек. 2022 г. |
30Наблюдать | CVE-2023-27578Эксплойта нет | Galaxy vulnerable to unauthorized modification of pages/visualizations due to insufficient permission checkgalaxyproject · galaxy · CWE-284 | Высокая7,5 | — | 0,8 % | 20 мар. 2023 г. |
24Наблюдать | CVE-2018-1000516Эксплойта нет | The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Mangalaxyproject · galaxy · CWE-79 | Средняя6,1 | — | 1,1 % | 26 июн. 2018 г. |
21Наблюдать | CVE-2024-42346Proof of concept | Stored Cross Site Scripting (Stored XSS) in Galaxygalaxyproject · galaxy · CWE-79 | Средняя5,4 | — | 0,8 % | 20 сент. 2024 г. |
17Наблюдать | CVE-2023-42812Эксплойта нет | Galaxy vulnerable to Server Side Request Forgery during data importsgalaxyproject · galaxy · CWE-918 | Средняя4,3 | — | 0,4 % | 22 сент. 2023 г. |
- CVE-2015-1006239Наблюдать
galaxy-data-resource Command Line Template injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %galaxyproject · galaxy17 янв. 2023 г.
- CVE-2024-4235136Наблюдать
Possible Data Tampering & Loss of Public Datasets in Galaxy
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %galaxyproject · galaxy20 сент. 2024 г.
- CVE-2022-2347030Наблюдать
Arbitrary file access in the Galaxy data analysis platform
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %galaxyproject · galaxy6 дек. 2022 г.
- CVE-2023-2757830Наблюдать
Galaxy vulnerable to unauthorized modification of pages/visualizations due to insufficient permission check
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %galaxyproject · galaxy20 мар. 2023 г.
- CVE-2018-100051624Наблюдать
The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Man
СредняяCVSS 6,1Эксплойта нетEPSS 1 %galaxyproject · galaxy26 июн. 2018 г.
- CVE-2024-4234621Наблюдать
Stored Cross Site Scripting (Stored XSS) in Galaxy
СредняяCVSS 5,4Proof of conceptEPSS 1 %galaxyproject · galaxy20 сент. 2024 г.
- CVE-2023-4281217Наблюдать
Galaxy vulnerable to Server Side Request Forgery during data imports
СредняяCVSS 4,3Эксплойта нетEPSS 0 %galaxyproject · galaxy22 сент. 2023 г.