Записи Graphite project
7 опубликованных записей вендора graphite project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 14,3 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-707 Improper Neutralization3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2013-5093Готовый эксплойт | The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, whigraphite project · graphite · CWE-94 | Средняя6,8 | — | 38,7 % | 27 сент. 2013 г. |
35Наблюдать | CVE-2017-18638Proof of concept | send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF.graphite project · graphite · CWE-918 | Высокая7,5 | — | 15,3 % | 11 окт. 2019 г. |
28Наблюдать | CVE-2013-5942Эксплойта нет | Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted graphite project · graphite · CWE-94 | Средняя6,8 | — | 2,1 % | 27 сент. 2013 г. |
21Наблюдать | CVE-2022-4728Эксплойта нет | Graphite Web Cookie cross site scriptinggraphite project · graphite · CWE-707 | Средняя5,4 | — | 0,8 % | 27 дек. 2022 г. |
21Наблюдать | CVE-2022-4730Эксплойта нет | Graphite Web Absolute Time Range cross site scriptinggraphite project · graphite · CWE-707 | Средняя5,4 | — | 0,8 % | 27 дек. 2022 г. |
21Наблюдать | CVE-2022-4729Эксплойта нет | Graphite Web Template Name cross site scriptinggraphite project · graphite · CWE-707 | Средняя5,4 | — | 0,7 % | 27 дек. 2022 г. |
18Наблюдать | CVE-2013-5943Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML graphite project · graphite · CWE-79 | Средняя4,3 | — | 1,8 % | 27 сент. 2013 г. |
- CVE-2013-509339Наблюдать
The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, whi
СредняяCVSS 6,8Готовый эксплойтEPSS 39 %graphite project · graphite27 сент. 2013 г.
- CVE-2017-1863835Наблюдать
send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF.
ВысокаяCVSS 7,5Proof of conceptEPSS 15 %graphite project · graphite11 окт. 2019 г.
- CVE-2013-594228Наблюдать
Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted
СредняяCVSS 6,8Эксплойта нетEPSS 2 %graphite project · graphite27 сент. 2013 г.
- CVE-2022-472821Наблюдать
Graphite Web Cookie cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %graphite project · graphite27 дек. 2022 г.
- CVE-2022-473021Наблюдать
Graphite Web Absolute Time Range cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %graphite project · graphite27 дек. 2022 г.
- CVE-2022-472921Наблюдать
Graphite Web Template Name cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %graphite project · graphite27 дек. 2022 г.
- CVE-2013-594318Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Эксплойта нетEPSS 2 %graphite project · graphite27 сент. 2013 г.