Перейти к содержимому
Noroxi

Записи Sitecore

35 опубликованных записей вендора sitecore.

Профиль для исследователя

Попали в KEV
4 · 11,4 %
С эксплойтом
6 · 17,1 %
Pre-auth RCE
5
С записью об исправлении
2,9 %
Медиана: публикация → KEV
1133 дн.

Все записи

35 записей
  • CVE-2021-42237
    98Срочно

    Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achi

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %

    sitecore · experience platform5 нояб. 2021 г.

  • CVE-2019-9874
    94Срочно

    Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %

    sitecore · cms31 мая 2019 г.

  • CVE-2025-53690
    81Срочно

    Sitecore Products ViewState Deserialization Vulnerability

    КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 51 %

    sitecore · experience commerce3 сент. 2025 г.

  • CVE-2019-9875
    69На этой неделе

    Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 14 %

    sitecore · cms31 мая 2019 г.

  • CVE-2023-35813
    65На этой неделе

    Multiple Sitecore products allow remote code execution.

    КритическаяCVSS 9,8Proof of conceptEPSS 87 %

    sitecore · experience commerce17 июн. 2023 г.

  • CVE-2025-34509
    47В плане

    Sitecore XM and XP Hardcoded Credentials

    ВысокаяCVSS 7,5Proof of conceptEPSS 56 %

    sitecore · experience commerce17 июн. 2025 г.

  • CVE-2025-53693
    45В плане

    HTML Cache Poisoning through Unsafe Reflections

    КритическаяCVSS 9,8Proof of conceptEPSS 19 %

    sitecore · experience commerce3 сент. 2025 г.

  • CVE-2024-46938
    44В плане

    An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release thro

    ВысокаяCVSS 7,5Proof of conceptEPSS 47 %

    sitecore · experience commerce15 сент. 2024 г.

  • CVE-2025-34511
    44В плане

    Sitecore PowerShell Extension RCE via Unrestricted Upload

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 30 %

    sitecore · experience commerce17 июн. 2025 г.

  • CVE-2025-34510
    42В плане

    Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 24 %

    sitecore · experience commerce17 июн. 2025 г.

  • CVE-2019-12440
    40В плане

    The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the S

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    sitecore · rocks29 мая 2019 г.

  • CVE-2023-27068
    40В плане

    Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationR

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    sitecore · experience platform22 мая 2023 г.

  • CVE-2019-11080
    39Наблюдать

    Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863.

    ВысокаяCVSS 8,8Proof of conceptEPSS 14 %

    sitecore · experience platform6 июн. 2019 г.

  • CVE-2021-38366
    36Наблюдать

    Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code ex

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    sitecore · sitecore12 авг. 2021 г.

  • CVE-2023-33652
    36Наблюдать

    Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    sitecore · experience platform6 июн. 2023 г.

  • CVE-2023-33653
    36Наблюдать

    Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the componen

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    sitecore · experience platform6 июн. 2023 г.

  • CVE-2018-7669
    35Наблюдать

    An issue was discovered in Sitecore Sitecore.NET 8.1 rev.

    ВысокаяCVSS 7,5Proof of conceptEPSS 17 %

    sitecore · sitecore.net27 апр. 2018 г.

  • CVE-2025-53691
    35Наблюдать

    Sitecore Experience Remote Code Execution through Insecure Deserialization

    ВысокаяCVSS 8,8Proof of conceptEPSS 2 %

    sitecore · experience commerce3 сент. 2025 г.

  • CVE-2025-53694
    32Наблюдать

    Information Disclosure in ItemServices API

    ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

    sitecore · experience commerce3 сент. 2025 г.

  • CVE-2023-27067
    30Наблюдать

    Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via craft

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    sitecore · experience platform22 мая 2023 г.

  • CVE-2023-33651
    30Наблюдать

    An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initia

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    sitecore · experience commerce6 июн. 2023 г.

  • CVE-2009-4367
    29Наблюдать

    The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote a

    СредняяCVSS 6,8Proof of conceptEPSS 6 %

    sitecore · staging module21 дек. 2009 г.

  • CVE-2023-26262
    28Наблюдать

    An issue was discovered in Sitecore XP/XM 10.3.

    ВысокаяCVSS 7,2Proof of conceptEPSS 2 %

    sitecore · experience manager14 мар. 2023 г.

  • CVE-2023-27066
    26Наблюдать

    Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitr

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    sitecore · experience platform22 мая 2023 г.

  • CVE-2017-5965
    26Наблюдать

    The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZI

    СредняяCVSS 6,7Эксплойта нетEPSS 1 %

    sitecore · crm23 мая 2017 г.