Записи Orientdb
7 опубликованных записей вендора orientdb.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 14,3 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 57,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-269 Improper Privilege Management1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2017-11467Готовый эксплойт | OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackeorientdb · orientdb · CWE-269 | Критическая9,8 | — | 73,1 % | 19 июл. 2017 г. |
35Наблюдать | CVE-2015-2912Эксплойта нет | The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrorientdb · orientdb · CWE-352 | Высокая8,8 | — | 1,3 % | 31 дек. 2015 г. |
24Наблюдать | CVE-2015-2913Эксплойта нет | server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x borientdb · orientdb · CWE-200 | Средняя5,9 | — | 1,9 % | 31 дек. 2015 г. |
24Наблюдать | CVE-2015-2918Эксплойта нет | The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elemeorientdb · orientdb · CWE-20 | Средняя6,1 | — | 0,7 % | 31 дек. 2015 г. |
21Наблюдать | CVE-2019-25447Эксплойта нет | OrientDB 3.0.17 Cross-Site Request Forgeryorientdb · orientdb · CWE-352 | Средняя5,3 | — | 0,1 % | 20 февр. 2026 г. |
20Наблюдать | CVE-2019-25448Эксплойта нет | OrientDB 3.0.17 Stored Cross-Site Scripting via User Creationorientdb · orientdb · CWE-79 | Средняя5,1 | — | 0,3 % | 20 февр. 2026 г. |
20Наблюдать | CVE-2019-25449Эксплойта нет | OrientDB 3.0.17 Reflected Cross-Site Scripting via document endpointorientdb · orientdb · CWE-79 | Средняя5,1 | — | 0,2 % | 20 февр. 2026 г. |
- CVE-2017-1146761На этой неделе
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attacke
КритическаяCVSS 9,8Готовый эксплойтEPSS 73 %orientdb · orientdb19 июл. 2017 г.
- CVE-2015-291235Наблюдать
The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restr
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %orientdb · orientdb31 дек. 2015 г.
- CVE-2015-291324Наблюдать
server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x b
СредняяCVSS 5,9Эксплойта нетEPSS 2 %orientdb · orientdb31 дек. 2015 г.
- CVE-2015-291824Наблюдать
The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME eleme
СредняяCVSS 6,1Эксплойта нетEPSS 1 %orientdb · orientdb31 дек. 2015 г.
- CVE-2019-2544721Наблюдать
OrientDB 3.0.17 Cross-Site Request Forgery
СредняяCVSS 5,3Эксплойта нетEPSS 0 %orientdb · orientdb20 февр. 2026 г.
- CVE-2019-2544820Наблюдать
OrientDB 3.0.17 Stored Cross-Site Scripting via User Creation
СредняяCVSS 5,1Эксплойта нетEPSS 0 %orientdb · orientdb20 февр. 2026 г.
- CVE-2019-2544920Наблюдать
OrientDB 3.0.17 Reflected Cross-Site Scripting via document endpoint
СредняяCVSS 5,1Эксплойта нетEPSS 0 %orientdb · orientdb20 февр. 2026 г.