Записи Intermesh
12 опубликованных записей вендора intermesh.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-502 Deserialization of Untrusted Data1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2026-34838Proof of concept | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`intermesh · group-office · CWE-502 | Критическая9,9 | — | 1,0 % | 2 апр. 2026 г. |
37Наблюдать | CVE-2026-27947Эксплойта нет | Group-Office Vulnerable to Remote Code Execution (RCE)intermesh · group-office · CWE-88 | Критическая9,4 | — | 1,0 % | 27 февр. 2026 г. |
35Наблюдать | CVE-2026-33755Эксплойта нет | Authenticated SQL Injection in Contact/query addressBookIds filterintermesh · group-office · CWE-89 | Высокая8,8 | — | 0,5 % | 27 мар. 2026 г. |
30Наблюдать | CVE-2010-3428Proof of concept | SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commaintermesh · group-office · CWE-89 | Высокая7,5 | — | 1,0 % | 16 сент. 2010 г. |
28Наблюдать | CVE-2026-27832Эксплойта нет | Group-Office Has Authenticated SQL Injection in advancedQueryData.comparatorintermesh · group-office · CWE-89 | Высокая7,1 | — | 0,5 % | 27 февр. 2026 г. |
27Наблюдать | CVE-2025-48366Эксплойта нет | GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actionsintermesh · group-office · CWE-79 | Средняя6,9 | — | 0,3 % | 22 мая 2025 г. |
23Наблюдать | CVE-2025-48368Эксплойта нет | GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Executionintermesh · group-office · CWE-79 | Средняя5,8 | — | 0,3 % | 22 мая 2025 г. |
21Наблюдать | CVE-2025-48369Эксплойта нет | GroupOffice vulnerable to Stored XSS in Tasks Comment Sectionintermesh · group-office · CWE-79 | Средняя5,3 | — | 0,3 % | 22 мая 2025 г. |
21Наблюдать | CVE-2025-48993Эксплойта нет | Group-Office vulnerable to reflected XSS via Look and Feel Formatting inputintermesh · group-office · CWE-79 | Средняя5,3 | — | 0,3 % | 16 июн. 2025 г. |
20Наблюдать | CVE-2026-30238Эксплойта нет | Group-Office: Reflected XSS in JavaScript contextintermesh · group-office · CWE-79 | Средняя5,1 | — | 0,3 % | 6 мар. 2026 г. |
20Наблюдать | CVE-2025-48992Эксплойта нет | Group-Office vulnerable to blind XSSintermesh · group-office · CWE-79 | Средняя5,2 | — | 0,3 % | 16 июн. 2025 г. |
8Наблюдать | CVE-2026-30237Эксплойта нет | Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php)intermesh · group-office · CWE-79 | Низкая2,1 | — | 0,3 % | 6 мар. 2026 г. |
- CVE-2026-3483839Наблюдать
Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`
КритическаяCVSS 9,9Proof of conceptEPSS 1 %intermesh · group-office2 апр. 2026 г.
- CVE-2026-2794737Наблюдать
Group-Office Vulnerable to Remote Code Execution (RCE)
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %intermesh · group-office27 февр. 2026 г.
- CVE-2026-3375535Наблюдать
Authenticated SQL Injection in Contact/query addressBookIds filter
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %intermesh · group-office27 мар. 2026 г.
- CVE-2010-342830Наблюдать
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL comma
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %intermesh · group-office16 сент. 2010 г.
- CVE-2026-2783228Наблюдать
Group-Office Has Authenticated SQL Injection in advancedQueryData.comparator
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %intermesh · group-office27 февр. 2026 г.
- CVE-2025-4836627Наблюдать
GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions
СредняяCVSS 6,9Эксплойта нетEPSS 0 %intermesh · group-office22 мая 2025 г.
- CVE-2025-4836823Наблюдать
GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Execution
СредняяCVSS 5,8Эксплойта нетEPSS 0 %intermesh · group-office22 мая 2025 г.
- CVE-2025-4836921Наблюдать
GroupOffice vulnerable to Stored XSS in Tasks Comment Section
СредняяCVSS 5,3Эксплойта нетEPSS 0 %intermesh · group-office22 мая 2025 г.
- CVE-2025-4899321Наблюдать
Group-Office vulnerable to reflected XSS via Look and Feel Formatting input
СредняяCVSS 5,3Эксплойта нетEPSS 0 %intermesh · group-office16 июн. 2025 г.
- CVE-2026-3023820Наблюдать
Group-Office: Reflected XSS in JavaScript context
СредняяCVSS 5,1Эксплойта нетEPSS 0 %intermesh · group-office6 мар. 2026 г.
- CVE-2025-4899220Наблюдать
Group-Office vulnerable to blind XSS
СредняяCVSS 5,2Эксплойта нетEPSS 0 %intermesh · group-office16 июн. 2025 г.
- CVE-2026-302378Наблюдать
Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php)
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %intermesh · group-office6 мар. 2026 г.