Записи mmonit
4 опубликованных записей вендора mmonit.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-255 Credentials Management Errors1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2014-6607Proof of concept | M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the passwmmonit · m\/monit · CWE-255 | Высокая7,5 | — | 6,6 % | 6 окт. 2014 г. |
28Наблюдать | CVE-2014-6409Proof of concept | Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of adminismmonit · m\/monit · CWE-352 | Средняя6,8 | — | 2,3 % | 6 окт. 2014 г. |
26Наблюдать | CVE-2016-7067Эксплойта нет | Monit before version 5.20.0 is vulnerable to a cross site request forgery attack.mmonit · monit · CWE-352 | Средняя6,5 | — | 0,9 % | 10 сент. 2018 г. |
25Наблюдать | CVE-2019-11454Эксплойта нет | Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introdmmonit · monit · CWE-79 | Средняя6,1 | — | 2,4 % | 22 апр. 2019 г. |
- CVE-2014-660732Наблюдать
M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the passw
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %mmonit · m\/monit6 окт. 2014 г.
- CVE-2014-640928Наблюдать
Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of adminis
СредняяCVSS 6,8Proof of conceptEPSS 2 %mmonit · m\/monit6 окт. 2014 г.
- CVE-2016-706726Наблюдать
Monit before version 5.20.0 is vulnerable to a cross site request forgery attack.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %mmonit · monit10 сент. 2018 г.
- CVE-2019-1145425Наблюдать
Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introd
СредняяCVSS 6,1Эксплойта нетEPSS 2 %mmonit · monit22 апр. 2019 г.