Записи MITRE
15 опубликованных записей вендора mitre.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 6,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-269 Improper Privilege Management1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2021-42561Proof of concept | An issue was discovered in CALDERA 2.8.1.mitre · caldera · CWE-74 | Высокая8,8 | — | 19,6 % | 12 янв. 2022 г. |
41В плане | CVE-2008-4704Proof of concept | PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via mitre · sezhoo · CWE-94 | Критическая10,0 | — | 3,5 % | 23 окт. 2008 г. |
36Наблюдать | CVE-2020-19907Эксплойта нет | A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command omitre · caldera · CWE-78 | Высокая8,8 | — | 3,0 % | 12 июл. 2021 г. |
36Наблюдать | CVE-2021-42560Proof of concept | An issue was discovered in CALDERA 2.9.0.mitre · caldera · CWE-611 | Высокая8,8 | — | 2,1 % | 12 янв. 2022 г. |
36Наблюдать | CVE-2021-42559Proof of concept | An issue was discovered in CALDERA 2.8.1.mitre · caldera · CWE-77 | Высокая8,8 | — | 2,0 % | 12 янв. 2022 г. |
32Наблюдать | CVE-2021-42562Proof of concept | An issue was discovered in CALDERA 2.8.1.mitre · caldera · CWE-269 | Высокая8,1 | — | 1,2 % | 12 янв. 2022 г. |
30Наблюдать | CVE-2022-31004Эксплойта нет | Potential secrets being logged to disk in CVE Servicesmitre · cve-services · CWE-779 | Высокая7,5 | — | 1,0 % | 2 июн. 2022 г. |
28Наблюдать | CVE-2021-46561Эксплойта нет | controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizamitre · cve services · CWE-863 | Высокая7,2 | — | 0,8 % | 26 янв. 2022 г. |
24Наблюдать | CVE-2021-42558Proof of concept | An issue was discovered in CALDERA 2.8.1.mitre · caldera · CWE-79 | Средняя6,1 | — | 1,1 % | 12 янв. 2022 г. |
24Наблюдать | CVE-2022-40606Эксплойта нет | MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability thmitre · caldera · CWE-79 | Средняя6,1 | — | 0,5 % | 17 окт. 2022 г. |
24Наблюдать | CVE-2022-40605Эксплойта нет | MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability thmitre · caldera · CWE-79 | Средняя6,1 | — | 0,5 % | 17 окт. 2022 г. |
21Наблюдать | CVE-2020-10807Эксплойта нет | auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host heademitre · caldera · CWE-290 | Средняя5,3 | — | 1,4 % | 22 мар. 2020 г. |
21Наблюдать | CVE-2020-14462Эксплойта нет | CALDERA 2.7.0 allows XSS via the Operation Name box.mitre · caldera · CWE-79 | Средняя5,4 | — | 0,6 % | 19 июн. 2020 г. |
21Наблюдать | CVE-2022-41139Эксплойта нет | MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commitre · caldera · CWE-79 | Средняя5,4 | — | 0,6 % | 17 окт. 2022 г. |
13Наблюдать | CVE-2023-51792Эксплойта нет | Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding theCWE-121 | Низкая3,3 | — | 0,2 % | 19 апр. 2024 г. |
- CVE-2021-4256141В плане
An issue was discovered in CALDERA 2.8.1.
ВысокаяCVSS 8,8Proof of conceptEPSS 20 %mitre · caldera12 янв. 2022 г.
- CVE-2008-470441В плане
PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via
КритическаяCVSS 10,0Proof of conceptEPSS 4 %mitre · sezhoo23 окт. 2008 г.
- CVE-2020-1990736Наблюдать
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command o
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %mitre · caldera12 июл. 2021 г.
- CVE-2021-4256036Наблюдать
An issue was discovered in CALDERA 2.9.0.
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %mitre · caldera12 янв. 2022 г.
- CVE-2021-4255936Наблюдать
An issue was discovered in CALDERA 2.8.1.
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %mitre · caldera12 янв. 2022 г.
- CVE-2021-4256232Наблюдать
An issue was discovered in CALDERA 2.8.1.
ВысокаяCVSS 8,1Proof of conceptEPSS 1 %mitre · caldera12 янв. 2022 г.
- CVE-2022-3100430Наблюдать
Potential secrets being logged to disk in CVE Services
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mitre · cve-services2 июн. 2022 г.
- CVE-2021-4656128Наблюдать
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organiza
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %mitre · cve services26 янв. 2022 г.
- CVE-2021-4255824Наблюдать
An issue was discovered in CALDERA 2.8.1.
СредняяCVSS 6,1Proof of conceptEPSS 1 %mitre · caldera12 янв. 2022 г.
- CVE-2022-4060624Наблюдать
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability th
СредняяCVSS 6,1Эксплойта нетEPSS 0 %mitre · caldera17 окт. 2022 г.
- CVE-2022-4060524Наблюдать
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability th
СредняяCVSS 6,1Эксплойта нетEPSS 0 %mitre · caldera17 окт. 2022 г.
- CVE-2020-1080721Наблюдать
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host heade
СредняяCVSS 5,3Эксплойта нетEPSS 1 %mitre · caldera22 мар. 2020 г.
- CVE-2020-1446221Наблюдать
CALDERA 2.7.0 allows XSS via the Operation Name box.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %mitre · caldera19 июн. 2020 г.
- CVE-2022-4113921Наблюдать
MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary com
СредняяCVSS 5,4Эксплойта нетEPSS 1 %mitre · caldera17 окт. 2022 г.
- CVE-2023-5179213Наблюдать
Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %19 апр. 2024 г.