Перейти к содержимому
Noroxi

Записи smartypantsplugins

15 опубликованных записей вендора smartypantsplugins.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 6,7 %
Pre-auth RCE
1
С записью об исправлении
20 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

15 записей
  • CVE-2021-24347
    51В плане

    SP Project & Document Manager <2 4.22 - Authenticated Shell Upload

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 54 %

    smartypantsplugins · sp project \& document manager14 июн. 2021 г.

  • CVE-2021-4225
    36Наблюдать

    SP Project & Document Manager < 4.24 - Subscriber+ Shell Upload

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    smartypantsplugins · sp project \& document manager25 апр. 2022 г.

  • CVE-2023-3063
    35Наблюдать

    SP Project & Document Manager <= 4.67 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    smartypantsplugins · sp project \& document manager29 июн. 2023 г.

  • CVE-2023-36677
    35Наблюдать

    WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to SQL Injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    smartypantsplugins · sp project \& document manager3 нояб. 2023 г.

  • CVE-2024-24868
    35Наблюдать

    WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL Injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    smartypantsplugins · sp project \& document manager28 февр. 2024 г.

  • CVE-2014-9178
    31Наблюдать

    Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-docum

    ВысокаяCVSS 7,5Proof of conceptEPSS 5 %

    smartypantsplugins · sp project \& document manager2 дек. 2014 г.

  • CVE-2021-38324
    31Наблюдать

    SP Rental Manager <= 1.5.3 Unauthenticated SQL Injection

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    smartypantsplugins · sp rental manager9 сент. 2021 г.

  • CVE-2022-1551
    26Наблюдать

    SP Project & Document Manager < 4.58 - Sensitive File Disclosure

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    smartypantsplugins · sp project \& document manager25 июл. 2022 г.

  • CVE-2024-37224
    26Наблюдать

    WordPress SP Project & Document Manager plugin <= 4.71 - Directory Traversal vulnerability

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    smartypantsplugins · sp project \& document manager9 июл. 2024 г.

  • CVE-2024-3749
    26Наблюдать

    SP Project & Document Manager <= 4.71 - Subscriber+ File Download via IDOR

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    smartypantsplugins · sp project \& document manager15 мая 2024 г.

  • CVE-2024-3748
    26Наблюдать

    SP Project & Document Manager <= 4.71 - Data Update via IDOR

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    smartypantsplugins · sp project \& document manager15 мая 2024 г.

  • CVE-2021-38315
    24Наблюдать

    SP Project & Document Manager <= 4.25 Reflected Cross-Site Scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    smartypantsplugins · sp project \& document manager16 авг. 2021 г.

  • CVE-2022-34857
    24Наблюдать

    WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerability

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    smartypantsplugins · sp project \& document manager22 авг. 2022 г.

  • CVE-2023-36530
    19Наблюдать

    WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to Cross Site Scripting (XSS)

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    smartypantsplugins · sp project \& document manager10 авг. 2023 г.

  • CVE-2013-3529
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote

    СредняяCVSS 4,3Proof of conceptEPSS 5 %

    wordpress · wordpress10 мая 2013 г.