Записи LiquidFiles
8 опубликованных записей вендора liquidfiles.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 12,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-24 Path Traversal: '../filedir'1
- CWE-305 Authentication Bypass by Primary Weakness1
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2021-43397Эксплойта нет | LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.liquidfiles · liquidfiles · CWE-522 | Высокая8,8 | — | 3,8 % | 11 нояб. 2021 г. |
36Наблюдать | CVE-2020-29071Эксплойта нет | An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19.liquidfiles · liquidfiles · CWE-79 | Критическая9,0 | — | 1,7 % | 24 нояб. 2020 г. |
35Наблюдать | CVE-2025-46093Эксплойта нет | LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as liquidfiles · liquidfiles · CWE-732 | Высокая8,8 | — | 0,5 % | 4 авг. 2025 г. |
29Наблюдать | CVE-2025-56132Proof of concept | LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality.liquidfiles · liquidfiles · CWE-305 | Высокая7,3 | — | 0,7 % | 30 сент. 2025 г. |
24Наблюдать | CVE-2020-29072Эксплойта нет | A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19.liquidfiles · liquidfiles · CWE-829 | Средняя6,1 | — | 0,7 % | 24 нояб. 2020 г. |
24Наблюдать | CVE-2023-4393Эксплойта нет | HTML and SMTP Injection in LiquidFilesliquidfiles · liquidfiles · CWE-116 | Средняя6,1 | — | 0,3 % | 29 окт. 2023 г. |
21Наблюдать | CVE-2021-30140Эксплойта нет | LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator.liquidfiles · liquidfiles · CWE-79 | Средняя5,4 | — | 1,4 % | 6 апр. 2021 г. |
15Наблюдать | CVE-2025-46094Эксплойта нет | LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript.liquidfiles · liquidfiles · CWE-24 | Низкая3,8 | — | 0,5 % | 4 авг. 2025 г. |
- CVE-2021-4339736Наблюдать
LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %liquidfiles · liquidfiles11 нояб. 2021 г.
- CVE-2020-2907136Наблюдать
An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19.
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %liquidfiles · liquidfiles24 нояб. 2020 г.
- CVE-2025-4609335Наблюдать
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %liquidfiles · liquidfiles4 авг. 2025 г.
- CVE-2025-5613229Наблюдать
LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality.
ВысокаяCVSS 7,3Proof of conceptEPSS 1 %liquidfiles · liquidfiles30 сент. 2025 г.
- CVE-2020-2907224Наблюдать
A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %liquidfiles · liquidfiles24 нояб. 2020 г.
- CVE-2023-439324Наблюдать
HTML and SMTP Injection in LiquidFiles
СредняяCVSS 6,1Эксплойта нетEPSS 0 %liquidfiles · liquidfiles29 окт. 2023 г.
- CVE-2021-3014021Наблюдать
LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %liquidfiles · liquidfiles6 апр. 2021 г.
- CVE-2025-4609415Наблюдать
LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript.
НизкаяCVSS 3,8Эксплойта нетEPSS 1 %liquidfiles · liquidfiles4 авг. 2025 г.