Записи rws
10 опубликованных записей вендора rws.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-287 Improper Authentication1
- CWE-331 Insufficient Entropy1
- CWE-284 Improper Access Control1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-918 Server-Side Request Forgery (SSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-2022-34267Proof of concept | An issue was discovered in RWS WorldServer before 11.7.3.rws · worldserver · CWE-287 | Критическая9,8 | — | 42,2 % | 25 дек. 2023 г. |
39Наблюдать | CVE-2022-34268Эксплойта нет | An issue was discovered in RWS WorldServer before 11.7.3.rws · worldserver · CWE-502 | Критическая9,8 | — | 1,5 % | 25 дек. 2023 г. |
39Наблюдать | CVE-2022-34270Эксплойта нет | An issue was discovered in RWS WorldServer before 11.7.3.rws · worldserver · CWE-284 | Критическая9,8 | — | 0,9 % | 28 февр. 2024 г. |
36Наблюдать | CVE-2022-34269Эксплойта нет | An issue was discovered in RWS WorldServer before 11.7.3.rws · worldserver · CWE-918 | Высокая8,8 | — | 1,7 % | 28 февр. 2024 г. |
30Наблюдать | CVE-2005-4548Эксплойта нет | SQL injection vulnerability in the "user area" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL commarws · statistics counter | Высокая7,5 | — | 1,2 % | 28 дек. 2005 г. |
26Наблюдать | CVE-2024-50848Proof of concept | An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to accerws · worldserver · CWE-611 | Средняя6,5 | — | 1,2 % | 18 нояб. 2024 г. |
24Наблюдать | CVE-2024-43024Эксплойта нет | Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary wrws · multitrans · CWE-79 | Средняя6,1 | — | 0,3 % | 18 сент. 2024 г. |
24Наблюдать | CVE-2024-43025Эксплойта нет | An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a rws · multitrans · CWE-79 | Средняя6,1 | — | 0,3 % | 18 сент. 2024 г. |
23Наблюдать | CVE-2023-38357Proof of concept | Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessiorws · worldserver · CWE-331 | Средняя5,3 | — | 5,3 % | 1 авг. 2023 г. |
19Наблюдать | CVE-2024-50849Proof of concept | A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attackerrws · worldserver · CWE-79 | Средняя4,8 | — | 0,5 % | 18 нояб. 2024 г. |
- CVE-2022-3426752В плане
An issue was discovered in RWS WorldServer before 11.7.3.
КритическаяCVSS 9,8Proof of conceptEPSS 42 %rws · worldserver25 дек. 2023 г.
- CVE-2022-3426839Наблюдать
An issue was discovered in RWS WorldServer before 11.7.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rws · worldserver25 дек. 2023 г.
- CVE-2022-3427039Наблюдать
An issue was discovered in RWS WorldServer before 11.7.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rws · worldserver28 февр. 2024 г.
- CVE-2022-3426936Наблюдать
An issue was discovered in RWS WorldServer before 11.7.3.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %rws · worldserver28 февр. 2024 г.
- CVE-2005-454830Наблюдать
SQL injection vulnerability in the "user area" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL comma
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rws · statistics counter28 дек. 2005 г.
- CVE-2024-5084826Наблюдать
An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to acce
СредняяCVSS 6,5Proof of conceptEPSS 1 %rws · worldserver18 нояб. 2024 г.
- CVE-2024-4302424Наблюдать
Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary w
СредняяCVSS 6,1Эксплойта нетEPSS 0 %rws · multitrans18 сент. 2024 г.
- CVE-2024-4302524Наблюдать
An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a
СредняяCVSS 6,1Эксплойта нетEPSS 0 %rws · multitrans18 сент. 2024 г.
- CVE-2023-3835723Наблюдать
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessio
СредняяCVSS 5,3Proof of conceptEPSS 5 %rws · worldserver1 авг. 2023 г.
- CVE-2024-5084919Наблюдать
A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attacker
СредняяCVSS 4,8Proof of conceptEPSS 0 %rws · worldserver18 нояб. 2024 г.