Записи Keyfactor
11 опубликованных записей вендора keyfactor.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-284 Improper Access Control3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-642 External Control of Critical State Data1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-33872Эксплойта нет | Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of CWE-89 | Критическая9,8 | — | 0,5 % | 20 авг. 2024 г. |
32Наблюдать | CVE-2023-34196Эксплойта нет | In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an akeyfactor · ejbca · CWE-287 | Высокая8,2 | — | 0,4 % | 2 авг. 2023 г. |
30Наблюдать | CVE-2024-42006Эксплойта нет | Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.keyfactor · aws orchestrator · CWE-200 | Высокая7,5 | — | 0,4 % | 20 авг. 2024 г. |
30Наблюдать | CVE-2024-34458Эксплойта нет | Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.keyfactor · command · CWE-89 | Высокая7,5 | — | 0,4 % | 20 авг. 2024 г. |
26Наблюдать | CVE-2025-47222Эксплойта нет | A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2.keyfactor · signserver · CWE-284 | Средняя6,5 | — | 0,3 % | 13 нояб. 2025 г. |
21Наблюдать | CVE-2022-39834Эксплойта нет | A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2.keyfactor · primekey ejbca · CWE-79 | Средняя5,4 | — | 0,4 % | 17 нояб. 2022 г. |
21Наблюдать | CVE-2022-42954Эксплойта нет | Keyfactor EJBCA before 7.10.0 allows XSS.keyfactor · kefactor ejbca · CWE-79 | Средняя5,4 | — | 0,4 % | 17 нояб. 2022 г. |
21Наблюдать | CVE-2025-47220Эксплойта нет | A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which keyfactor · signserver · CWE-284 | Средняя5,3 | — | 0,3 % | 13 нояб. 2025 г. |
21Наблюдать | CVE-2025-47221Эксплойта нет | An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2.keyfactor · signserver · CWE-284 | Средняя5,3 | — | 0,2 % | 13 нояб. 2025 г. |
18Наблюдать | CVE-2025-26787Эксплойта нет | An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2.keyfactor · signserver · CWE-642 | Средняя4,7 | — | 0,1 % | 22 дек. 2025 г. |
12Наблюдать | CVE-2024-36066Эксплойта нет | The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RFkeyfactor · ejbca | Низкая3,1 | — | 0,2 % | 12 сент. 2024 г. |
- CVE-2024-3387239Наблюдать
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %20 авг. 2024 г.
- CVE-2023-3419632Наблюдать
In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an a
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %keyfactor · ejbca2 авг. 2023 г.
- CVE-2024-4200630Наблюдать
Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %keyfactor · aws orchestrator20 авг. 2024 г.
- CVE-2024-3445830Наблюдать
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %keyfactor · command20 авг. 2024 г.
- CVE-2025-4722226Наблюдать
A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %keyfactor · signserver13 нояб. 2025 г.
- CVE-2022-3983421Наблюдать
A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %keyfactor · primekey ejbca17 нояб. 2022 г.
- CVE-2022-4295421Наблюдать
Keyfactor EJBCA before 7.10.0 allows XSS.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %keyfactor · kefactor ejbca17 нояб. 2022 г.
- CVE-2025-4722021Наблюдать
A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which
СредняяCVSS 5,3Эксплойта нетEPSS 0 %keyfactor · signserver13 нояб. 2025 г.
- CVE-2025-4722121Наблюдать
An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %keyfactor · signserver13 нояб. 2025 г.
- CVE-2025-2678718Наблюдать
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2.
СредняяCVSS 4,7Эксплойта нетEPSS 0 %keyfactor · signserver22 дек. 2025 г.
- CVE-2024-3606612Наблюдать
The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RF
НизкаяCVSS 3,1Эксплойта нетEPSS 0 %keyfactor · ejbca12 сент. 2024 г.