Записи OutSystems
6 опубликованных записей вендора outsystems.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-427 Uncontrolled Search Path Element1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2021-29357Эксплойта нет | The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before outsystems · lifetime management console · CWE-918 | Высокая8,6 | — | 1,0 % | 12 апр. 2021 г. |
31Наблюдать | CVE-2022-47636Proof of concept | A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739.outsystems · service studio · CWE-427 | Высокая7,8 | — | 1,3 % | 10 авг. 2023 г. |
30Наблюдать | CVE-2025-61258Эксплойта нет | Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the booutsystems · platform server · CWE-444 | Высокая7,5 | — | 0,6 % | 9 дек. 2025 г. |
26Наблюдать | CVE-2020-29441Эксплойта нет | An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0.outsystems · outsystems · CWE-434 | Средняя6,5 | — | 1,0 % | 30 нояб. 2020 г. |
26Наблюдать | CVE-2019-12273Эксплойта нет | OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads.outsystems · outsystems · CWE-352 | Средняя6,5 | — | 0,5 % | 31 дек. 2019 г. |
24Наблюдать | CVE-2020-13639Эксплойта нет | A stored XSS vulnerability was discovered in the ECT Provider in OutSystems before 2020-09-04, affecting generated applications.outsystems · lifetime management console · CWE-79 | Средняя6,1 | — | 0,8 % | 31 авг. 2021 г. |
- CVE-2021-2935734Наблюдать
The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %outsystems · lifetime management console12 апр. 2021 г.
- CVE-2022-4763631Наблюдать
A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739.
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %outsystems · service studio10 авг. 2023 г.
- CVE-2025-6125830Наблюдать
Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the bo
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %outsystems · platform server9 дек. 2025 г.
- CVE-2020-2944126Наблюдать
An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %outsystems · outsystems30 нояб. 2020 г.
- CVE-2019-1227326Наблюдать
OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %outsystems · outsystems31 дек. 2019 г.
- CVE-2020-1363924Наблюдать
A stored XSS vulnerability was discovered in the ECT Provider in OutSystems before 2020-09-04, affecting generated applications.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %outsystems · lifetime management console31 авг. 2021 г.