Записи opensagres
2 опубликованных записей вендора opensagres.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine1
- CWE-611 Improper Restriction of XML External Entity Reference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
2 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2025-64087Proof of concept | A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackersopensagres · xdocreport · CWE-1336 | Критическая9,8 | — | 0,6 % | 20 янв. 2026 г. |
39Наблюдать | CVE-2025-65482Proof of concept | An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploadinopensagres · xdocreport · CWE-611 | Критическая9,8 | — | 0,6 % | 20 янв. 2026 г. |
- CVE-2025-6408739Наблюдать
A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers
КритическаяCVSS 9,8Proof of conceptEPSS 1 %opensagres · xdocreport20 янв. 2026 г.
- CVE-2025-6548239Наблюдать
An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploadin
КритическаяCVSS 9,8Proof of conceptEPSS 1 %opensagres · xdocreport20 янв. 2026 г.