Записи Parallels
155 опубликованных записей вендора parallels.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 12
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor20
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-125 Out-of-bounds Read8
- CWE-129 Improper Validation of Array Index7
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition7
- CWE-255 Credentials Management Errors6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
155 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2011-4749Эксплойта нет | The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete feparallels · parallels plesk panel · CWE-255 | Критическая10,0 | — | 2,2 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4739Эксплойта нет | The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a password form field without disabling the autocomplete featuparallels · parallels plesk panel · CWE-255 | Критическая10,0 | — | 2,2 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4757Эксплойта нет | Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easieparallels · parallels plesk small business panel · CWE-255 | Критическая10,0 | — | 2,2 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4730Эксплойта нет | The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabling the autparallels · parallels plesk panel · CWE-255 | Критическая10,0 | — | 2,2 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4768Эксплойта нет | The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter fparallels · parallels plesk small business panel | Критическая10,0 | — | 1,9 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4761Эксплойта нет | Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remotparallels · parallels plesk small business panel | Критическая10,0 | — | 1,8 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4744Эксплойта нет | The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 sends incorrect Content-Type headers for certain resources, which might parallels · parallels plesk panel | Критическая10,0 | — | 1,8 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4762Эксплойта нет | Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers tparallels · parallels plesk small business panel | Критическая10,0 | — | 1,8 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4743Эксплойта нет | The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 omits the Content-Type header's charset parameter for certain resources,parallels · parallels plesk panel | Критическая10,0 | — | 1,8 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4732Эксплойта нет | The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 omits the Content-Type header's charset parameter for cerparallels · parallels plesk panel | Критическая10,0 | — | 1,8 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4733Эксплойта нет | The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 sends incorrect Content-Type headers for certain resourceparallels · parallels plesk panel | Критическая10,0 | — | 1,8 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4755Эксплойта нет | Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which alparallels · parallels plesk small business panel · CWE-20 | Критическая10,0 | — | 1,8 % | 16 дек. 2011 г. |
41В плане | CVE-2011-4727Эксплойта нет | The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended fparallels · parallels plesk panel · CWE-20 | Критическая10,0 | — | 1,8 % | 16 дек. 2011 г. |
40В плане | CVE-2020-15860Эксплойта нет | Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution.parallels · remote application server | Критическая9,9 | — | 4,0 % | 24 июл. 2020 г. |
40В плане | CVE-2023-45894Эксплойта нет | The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a rparallels · remote application server | Критическая10,0 | — | 1,2 % | 14 дек. 2023 г. |
40В плане | CVE-2024-6240Эксплойта нет | Improper privilege management vulnerability in Parallels Desktopparallels · parallels desktop · CWE-269 | Критическая10,0 | — | 0,3 % | 21 июн. 2024 г. |
39Наблюдать | CVE-2013-4878Proof of concept | The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAliparallels · parallels plesk panel · CWE-264 | Высокая7,5 | — | 31,1 % | 18 июл. 2013 г. |
39Наблюдать | CVE-2024-34331Эксплойта нет | A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted mCWE-269 | Критическая9,8 | — | 1,0 % | 23 сент. 2024 г. |
38Наблюдать | CVE-2007-4009Proof of concept | PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackparallels · confixx · CWE-94 | Критическая9,3 | — | 4,3 % | 25 июл. 2007 г. |
38Наблюдать | CVE-2011-4851Эксплойта нет | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete featurparallels · parallels plesk panel · CWE-255 | Критическая9,3 | — | 1,9 % | 16 дек. 2011 г. |
37Наблюдать | CVE-2011-4854Эксплойта нет | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Coparallels · parallels plesk panel | Критическая9,3 | — | 1,6 % | 16 дек. 2011 г. |
37Наблюдать | CVE-2011-4856Эксплойта нет | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might aparallels · parallels plesk panel | Критическая9,3 | — | 1,6 % | 16 дек. 2011 г. |
37Наблюдать | CVE-2011-4855Эксплойта нет | The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header's charset parameter for certain resources, parallels · parallels plesk panel | Критическая9,3 | — | 1,6 % | 16 дек. 2011 г. |
35Наблюдать | CVE-2025-31359Эксплойта нет | A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879).parallels · parallels desktop · CWE-22 | Высокая8,8 | — | 1,1 % | 3 июн. 2025 г. |
35Наблюдать | CVE-2020-8875Эксплойта нет | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123.parallels · parallels desktop · CWE-129 | Высокая8,8 | — | 0,5 % | 23 мар. 2020 г. |
- CVE-2011-474941В плане
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete fe
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2011-473941В плане
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates a password form field without disabling the autocomplete featu
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2011-475741В плане
Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easie
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk small business panel16 дек. 2011 г.
- CVE-2011-473041В плане
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 generates a password form field without disabling the aut
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2011-476841В плане
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter f
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk small business panel16 дек. 2011 г.
- CVE-2011-476141В плане
Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remot
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk small business panel16 дек. 2011 г.
- CVE-2011-474441В плане
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 sends incorrect Content-Type headers for certain resources, which might
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2011-476241В плане
Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers t
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk small business panel16 дек. 2011 г.
- CVE-2011-474341В плане
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 omits the Content-Type header's charset parameter for certain resources,
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2011-473241В плане
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 omits the Content-Type header's charset parameter for cer
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2011-473341В плане
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 sends incorrect Content-Type headers for certain resource
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2011-475541В плане
Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which al
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk small business panel16 дек. 2011 г.
- CVE-2011-472741В плане
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not properly validate string data that is intended f
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2020-1586040В плане
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution.
КритическаяCVSS 9,9Эксплойта нетEPSS 4 %parallels · remote application server24 июл. 2020 г.
- CVE-2023-4589440В плане
The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a r
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %parallels · remote application server14 дек. 2023 г.
- CVE-2024-624040В плане
Improper privilege management vulnerability in Parallels Desktop
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %parallels · parallels desktop21 июн. 2024 г.
- CVE-2013-487839Наблюдать
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAli
ВысокаяCVSS 7,5Proof of conceptEPSS 31 %parallels · parallels plesk panel18 июл. 2013 г.
- CVE-2024-3433139Наблюдать
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted m
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %23 сент. 2024 г.
- CVE-2007-400938Наблюдать
PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attack
КритическаяCVSS 9,3Proof of conceptEPSS 4 %parallels · confixx25 июл. 2007 г.
- CVE-2011-485138Наблюдать
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete featur
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2011-485437Наблюдать
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Co
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2011-485637Наблюдать
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might a
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2011-485537Наблюдать
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header's charset parameter for certain resources,
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %parallels · parallels plesk panel16 дек. 2011 г.
- CVE-2025-3135935Наблюдать
A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879).
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %parallels · parallels desktop3 июн. 2025 г.
- CVE-2020-887535Наблюдать
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %parallels · parallels desktop23 мар. 2020 г.