Записи thecontrolgroup
5 опубликованных записей вендора thecontrolgroup.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-281 Improper Preservation of Permissions1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2020-36070Эксплойта нет | Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php fithecontrolgroup · voyager · CWE-281 | Критическая9,8 | — | 1,1 % | 26 апр. 2023 г. |
28Наблюдать | CVE-2019-17050Эксплойта нет | An issue was discovered in the Voyager package through 1.2.7 for Laravel.thecontrolgroup · voyager · CWE-639 | Высокая7,2 | — | 1,2 % | 30 сент. 2019 г. |
27Наблюдать | CVE-2024-55415Proof of concept | DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.thecontrolgroup · voyager · CWE-22 | Средняя5,7 | — | 15,6 % | 30 янв. 2025 г. |
21Наблюдать | CVE-2024-55417Proof of concept | DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /athecontrolgroup · voyager · CWE-434 | Средняя4,3 | — | 14,1 % | 30 янв. 2025 г. |
20Наблюдать | CVE-2024-55416Proof of concept | DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass.thecontrolgroup · voyager · CWE-79 | Низкая3,5 | — | 20,3 % | 30 янв. 2025 г. |
- CVE-2020-3607039Наблюдать
Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php fi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %thecontrolgroup · voyager26 апр. 2023 г.
- CVE-2019-1705028Наблюдать
An issue was discovered in the Voyager package through 1.2.7 for Laravel.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %thecontrolgroup · voyager30 сент. 2019 г.
- CVE-2024-5541527Наблюдать
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
СредняяCVSS 5,7Proof of conceptEPSS 16 %thecontrolgroup · voyager30 янв. 2025 г.
- CVE-2024-5541721Наблюдать
DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /a
СредняяCVSS 4,3Proof of conceptEPSS 14 %thecontrolgroup · voyager30 янв. 2025 г.
- CVE-2024-5541620Наблюдать
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass.
НизкаяCVSS 3,5Proof of conceptEPSS 20 %thecontrolgroup · voyager30 янв. 2025 г.