Записи sixapart
50 опубликованных записей вендора sixapart.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 4 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 22 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')25
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-287 Improper Authentication2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
50 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
65На этой неделе | CVE-2021-20837Proof of concept | Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 rsixapart · movable type · CWE-78 | Критическая9,8 | — | 88,1 % | 26 окт. 2021 г. |
53В плане | CVE-2015-1592Готовый эксплойт | Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::tdebian · debian linux · CWE-74 | Высокая7,5 | — | 75,4 % | 19 февр. 2015 г. |
44В плане | CVE-2013-0209Готовый эксплойт | lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migrsixapart · movable type · CWE-287 | Высокая7,5 | — | 45,2 % | 22 янв. 2013 г. |
40В плане | CVE-2022-38078Эксплойта нет | Movable Type XMLRPC API provided by Six Apart Ltd.sixapart · movable type · CWE-94 | Критическая9,8 | — | 2,1 % | 24 авг. 2022 г. |
40В плане | CVE-2010-4511Эксплойта нет | Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic sixapart · movabletype | Критическая10,0 | — | 1,5 % | 9 дек. 2010 г. |
40В плане | CVE-2010-4509Эксплойта нет | Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to tsixapart · movabletype | Критическая10,0 | — | 1,5 % | 9 дек. 2010 г. |
40В плане | CVE-2009-0752Эксплойта нет | Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vectors, possibly relatedsixapart · movable type | Критическая10,0 | — | 1,4 % | 2 мар. 2009 г. |
39Наблюдать | CVE-2016-5742Эксплойта нет | SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Tysixapart · movable type · CWE-89 | Критическая9,8 | — | 1,6 % | 23 янв. 2017 г. |
37Наблюдать | CVE-2026-25776Эксплойта нет | Movable Type provided by Six Apart Ltd.sixapart · movable type · CWE-94 | Критическая9,3 | — | 0,7 % | 8 апр. 2026 г. |
36Наблюдать | CVE-2020-5577Эксплойта нет | Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movablesixapart · movable type · CWE-434 | Высокая8,8 | — | 1,7 % | 13 мая 2020 г. |
35Наблюдать | CVE-2020-5576Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable sixapart · movable type · CWE-352 | Высокая8,8 | — | 0,8 % | 13 мая 2020 г. |
31Наблюдать | CVE-2015-0845Эксплойта нет | Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remosixapart · movabletype · CWE-94 | Высокая7,5 | — | 3,7 % | 17 апр. 2015 г. |
31Наблюдать | CVE-2013-2184Эксплойта нет | Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via thesixapart · movable type · CWE-17 | Высокая7,5 | — | 3,6 % | 27 мар. 2015 г. |
31Наблюдать | CVE-2012-0320Эксплойта нет | Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote attackers to take control of sessions via unspecified vectorssixapart · movable type | Высокая7,5 | — | 2,7 % | 3 мар. 2012 г. |
31Наблюдать | CVE-2011-5085Эксплойта нет | Unspecified vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to read or modify data via unknown vecsixapart · movable type | Высокая7,5 | — | 2,0 % | 2 апр. 2012 г. |
31Наблюдать | CVE-2014-9057Эксплойта нет | SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote atdebian · debian linux · CWE-89 | Высокая7,5 | — | 2,0 % | 16 дек. 2014 г. |
30Наблюдать | CVE-2010-3922Эксплойта нет | SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands visixapart · movabletype · CWE-89 | Высокая7,5 | — | 1,3 % | 9 дек. 2010 г. |
28Наблюдать | CVE-2022-43660Эксплойта нет | Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Psixapart · movable type · CWE-94 | Высокая7,2 | — | 1,0 % | 7 дек. 2022 г. |
27Наблюдать | CVE-2012-0317Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote sixapart · movable type · CWE-352 | Средняя6,8 | — | 1,1 % | 3 мар. 2012 г. |
27Наблюдать | CVE-2026-33088Эксплойта нет | Movable Type provided by Six Apart Ltd.sixapart · movable type · CWE-89 | Средняя6,9 | — | 0,5 % | 8 апр. 2026 г. |
26Наблюдать | CVE-2022-45113Эксплойта нет | Improper validation of syntactic correctness of input vulnerability exist in Movable Type series.sixapart · movable type · CWE-20 | Средняя6,5 | — | 0,6 % | 7 дек. 2022 г. |
24Наблюдать | CVE-2020-5575Эксплойта нет | Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advancedsixapart · movable type · CWE-79 | Средняя6,1 | — | 1,0 % | 13 мая 2020 г. |
24Наблюдать | CVE-2021-20810Эксплойта нет | Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series), sixapart · movable type · CWE-79 | Средняя6,1 | — | 0,9 % | 25 авг. 2021 г. |
24Наблюдать | CVE-2021-20814Эксплойта нет | Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable Type 7 r.4903 and earsixapart · movable type · CWE-79 | Средняя6,1 | — | 0,9 % | 25 авг. 2021 г. |
24Наблюдать | CVE-2021-20812Эксплойта нет | Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Typsixapart · movable type · CWE-79 | Средняя6,1 | — | 0,9 % | 25 авг. 2021 г. |
- CVE-2021-2083765На этой неделе
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r
КритическаяCVSS 9,8Proof of conceptEPSS 88 %sixapart · movable type26 окт. 2021 г.
- CVE-2015-159253В плане
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::t
ВысокаяCVSS 7,5Готовый эксплойтEPSS 75 %debian · debian linux19 февр. 2015 г.
- CVE-2013-020944В плане
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migr
ВысокаяCVSS 7,5Готовый эксплойтEPSS 45 %sixapart · movable type22 янв. 2013 г.
- CVE-2022-3807840В плане
Movable Type XMLRPC API provided by Six Apart Ltd.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %sixapart · movable type24 авг. 2022 г.
- CVE-2010-451140В плане
Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %sixapart · movabletype9 дек. 2010 г.
- CVE-2010-450940В плане
Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to t
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %sixapart · movabletype9 дек. 2010 г.
- CVE-2009-075240В плане
Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vectors, possibly related
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %sixapart · movable type2 мар. 2009 г.
- CVE-2016-574239Наблюдать
SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Ty
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %sixapart · movable type23 янв. 2017 г.
- CVE-2026-2577637Наблюдать
Movable Type provided by Six Apart Ltd.
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %sixapart · movable type8 апр. 2026 г.
- CVE-2020-557736Наблюдать
Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %sixapart · movable type13 мая 2020 г.
- CVE-2020-557635Наблюдать
Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sixapart · movable type13 мая 2020 г.
- CVE-2015-084531Наблюдать
Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remo
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %sixapart · movabletype17 апр. 2015 г.
- CVE-2013-218431Наблюдать
Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %sixapart · movable type27 мар. 2015 г.
- CVE-2012-032031Наблюдать
Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows remote attackers to take control of sessions via unspecified vectors
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %sixapart · movable type3 мар. 2012 г.
- CVE-2011-508531Наблюдать
Unspecified vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to read or modify data via unknown vec
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sixapart · movable type2 апр. 2012 г.
- CVE-2014-905731Наблюдать
SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote at
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %debian · debian linux16 дек. 2014 г.
- CVE-2010-392230Наблюдать
SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sixapart · movabletype9 дек. 2010 г.
- CVE-2022-4366028Наблюдать
Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with P
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %sixapart · movable type7 дек. 2022 г.
- CVE-2012-031727Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote
СредняяCVSS 6,8Эксплойта нетEPSS 1 %sixapart · movable type3 мар. 2012 г.
- CVE-2026-3308827Наблюдать
Movable Type provided by Six Apart Ltd.
СредняяCVSS 6,9Эксплойта нетEPSS 0 %sixapart · movable type8 апр. 2026 г.
- CVE-2022-4511326Наблюдать
Improper validation of syntactic correctness of input vulnerability exist in Movable Type series.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %sixapart · movable type7 дек. 2022 г.
- CVE-2020-557524Наблюдать
Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sixapart · movable type13 мая 2020 г.
- CVE-2021-2081024Наблюдать
Cross-site scripting vulnerability in Website Management screen of Movable Type (Movable Type 7 r.4903 and earlier (Movable Type 7 Series),
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sixapart · movable type25 авг. 2021 г.
- CVE-2021-2081424Наблюдать
Cross-site scripting vulnerability in Setting screen of ContentType Information Widget Plugin of Movable Type (Movable Type 7 r.4903 and ear
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sixapart · movable type25 авг. 2021 г.
- CVE-2021-2081224Наблюдать
Cross-site scripting vulnerability in Setting screen of Server Sync of Movable Type (Movable Type Advanced 7 r.4903 and earlier (Movable Typ
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sixapart · movable type25 авг. 2021 г.