Записи StrangeBee
5 опубликованных записей вендора strangebee.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-306 Missing Authentication for Critical Function1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-39069Эксплойта нет | An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentstrangebee · cortex · CWE-287 | Критическая9,8 | — | 0,9 % | 11 сент. 2023 г. |
36Наблюдать | CVE-2017-18376Эксплойта нет | An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write accestrangebee · thehive · CWE-264 | Высокая8,8 | — | 1,9 % | 2 июн. 2019 г. |
27Наблюдать | CVE-2026-63098Эксплойта нет | TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpointstrangebee · thehive · CWE-306 | Средняя6,9 | — | 0,4 % | 17 июл. 2026 г. |
21Наблюдать | CVE-2024-22876Эксплойта нет | StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which strangebee · thehive · CWE-79 | Средняя5,4 | — | 0,3 % | 19 янв. 2024 г. |
21Наблюдать | CVE-2024-22877Эксплойта нет | StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality.strangebee · thehive · CWE-79 | Средняя5,4 | — | 0,3 % | 19 янв. 2024 г. |
- CVE-2023-3906939Наблюдать
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authent
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %strangebee · cortex11 сент. 2023 г.
- CVE-2017-1837636Наблюдать
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write acce
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %strangebee · thehive2 июн. 2019 г.
- CVE-2026-6309827Наблюдать
TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
СредняяCVSS 6,9Эксплойта нетEPSS 0 %strangebee · thehive17 июл. 2026 г.
- CVE-2024-2287621Наблюдать
StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which
СредняяCVSS 5,4Эксплойта нетEPSS 0 %strangebee · thehive19 янв. 2024 г.
- CVE-2024-2287721Наблюдать
StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %strangebee · thehive19 янв. 2024 г.