Записи priority-software
10 опубликованных записей вендора priority-software.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-23459Эксплойта нет | Priority Windows – Command Execution via SQL Injectionpriority-software · priority · CWE-89 | Критическая9,8 | — | 0,9 % | 15 февр. 2023 г. |
39Наблюдать | CVE-2023-23460Эксплойта нет | Priority Web – Authentication bypasspriority-software · priority · CWE-287 | Критическая9,8 | — | 0,7 % | 15 февр. 2023 г. |
30Наблюдать | CVE-2024-41696Эксплойта нет | Priority PRI WEB Portal Add-On for Priority ERP on prem – CWE-200: Exposure of Sensitive Information to an Unauthorized Actorpriority · pri web portal add-on for priority erp on prem · CWE-200 | Высокая7,5 | — | 0,4 % | 30 июл. 2024 г. |
30Наблюдать | CVE-2024-41699Эксплойта нет | Priority – CWE-552: Files or Directories Accessible to External Partiespriority-software · priority · CWE-552 | Высокая7,5 | — | 0,3 % | 20 авг. 2024 г. |
30Наблюдать | CVE-2024-41698Эксплойта нет | Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actorpriority-software · priority · CWE-200 | Высокая7,5 | — | 0,3 % | 20 авг. 2024 г. |
25Наблюдать | CVE-2022-23173Эксплойта нет | Priority - Priority web Insecure direct object references (IDOR)priority-software · priority · CWE-639 | Средняя6,3 | — | 0,6 % | 6 июл. 2022 г. |
24Наблюдать | CVE-2021-26832Proof of concept | Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javapriority-software · priority enterprise management system · CWE-79 | Средняя6,1 | — | 0,8 % | 14 апр. 2021 г. |
24Наблюдать | CVE-2024-41697Эксплойта нет | Priority – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)priority-software · priority · CWE-80 | Средняя6,1 | — | 0,3 % | 20 авг. 2024 г. |
24Наблюдать | CVE-2024-41693Эксплойта нет | Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)priority-software · mashov · CWE-80 | Средняя6,1 | — | 0,3 % | 30 июл. 2024 г. |
17Наблюдать | CVE-2022-23172Эксплойта нет | Priority - Priority User Enumerationpriority-software · priority · CWE-640 | Средняя4,3 | — | 0,4 % | 6 июл. 2022 г. |
- CVE-2023-2345939Наблюдать
Priority Windows – Command Execution via SQL Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %priority-software · priority15 февр. 2023 г.
- CVE-2023-2346039Наблюдать
Priority Web – Authentication bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %priority-software · priority15 февр. 2023 г.
- CVE-2024-4169630Наблюдать
Priority PRI WEB Portal Add-On for Priority ERP on prem – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %priority · pri web portal add-on for priority erp on prem30 июл. 2024 г.
- CVE-2024-4169930Наблюдать
Priority – CWE-552: Files or Directories Accessible to External Parties
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %priority-software · priority20 авг. 2024 г.
- CVE-2024-4169830Наблюдать
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %priority-software · priority20 авг. 2024 г.
- CVE-2022-2317325Наблюдать
Priority - Priority web Insecure direct object references (IDOR)
СредняяCVSS 6,3Эксплойта нетEPSS 1 %priority-software · priority6 июл. 2022 г.
- CVE-2021-2683224Наблюдать
Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute java
СредняяCVSS 6,1Proof of conceptEPSS 1 %priority-software · priority enterprise management system14 апр. 2021 г.
- CVE-2024-4169724Наблюдать
Priority – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %priority-software · priority20 авг. 2024 г.
- CVE-2024-4169324Наблюдать
Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %priority-software · mashov30 июл. 2024 г.
- CVE-2022-2317217Наблюдать
Priority - Priority User Enumeration
СредняяCVSS 4,3Эксплойта нетEPSS 0 %priority-software · priority6 июл. 2022 г.