Записи thingsboard
15 опубликованных записей вендора thingsboard.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 26,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-269 Improper Privilege Management2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-791 Incomplete Filtering of Special Elements1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2022-40004Эксплойта нет | Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Lothingsboard · thingsboard · CWE-79 | Критическая9,6 | — | 0,9 % | 15 дек. 2022 г. |
35Наблюдать | CVE-2020-27687Эксплойта нет | ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails.thingsboard · thingsboard · CWE-20 | Высокая8,8 | — | 1,5 % | 18 дек. 2020 г. |
35Наблюдать | CVE-2022-48341Эксплойта нет | ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation.thingsboard · thingsboard · CWE-269 | Высокая8,8 | — | 1,0 % | 23 февр. 2023 г. |
35Наблюдать | CVE-2022-45608Эксплойта нет | An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and thingsboard · thingsboard · CWE-269 | Высокая8,8 | — | 0,9 % | 1 мар. 2023 г. |
35Наблюдать | CVE-2023-45303Эксплойта нет | ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supthingsboard · thingsboard · CWE-74 | Высокая8,8 | — | 0,9 % | 6 окт. 2023 г. |
32Наблюдать | CVE-2023-26462Эксплойта нет | ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escthingsboard · thingsboard · CWE-798 | Высокая8,1 | — | 1,1 % | 23 февр. 2023 г. |
28Наблюдать | CVE-2025-34282Proof of concept | ThingsBoard < v4.2.1 SVG Image SSRFthingsboard · thingsboard · CWE-918 | Средняя6,9 | — | 1,8 % | 17 окт. 2025 г. |
26Наблюдать | CVE-2024-3270Эксплойта нет | ThingsBoard AdvancedFeature access controlthingsboard · thingsboard · CWE-284 | Средняя6,5 | — | 0,6 % | 3 апр. 2024 г. |
26Наблюдать | CVE-2024-55466Proof of concept | An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 thingsboard · thingsboard · CWE-77 | Средняя6,5 | — | 0,4 % | 12 мая 2025 г. |
24Наблюдать | CVE-2024-9358Эксплойта нет | ThingsBoard HTTP RPC API resource consumptionthingsboard · thingsboard · CWE-400 | Средняя6,0 | — | 0,8 % | 30 сент. 2024 г. |
24Наблюдать | CVE-2025-34281Эксплойта нет | Stored Cross-Site Scripting (XSS) in ThingsBoardthingsboard · thingsboard · CWE-79 | Средняя6,2 | — | 0,4 % | 17 окт. 2025 г. |
21Наблюдать | CVE-2022-31861Эксплойта нет | Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.thingsboard · thingsboard · CWE-79 | Средняя5,4 | — | 0,6 % | 13 сент. 2022 г. |
20Наблюдать | CVE-2021-42750Proof of concept | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injecthingsboard · thingsboard · CWE-79 | Средняя4,8 | — | 3,1 % | 12 авг. 2022 г. |
20Наблюдать | CVE-2021-42751Proof of concept | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injecthingsboard · thingsboard · CWE-79 | Средняя4,8 | — | 3,1 % | 12 авг. 2022 г. |
8Наблюдать | CVE-2025-9094Эксплойта нет | ThingsBoard Add Gateway special elements used in a template enginethingsboard · thingsboard · CWE-791 | Низкая2,1 | — | 0,3 % | 17 авг. 2025 г. |
- CVE-2022-4000438Наблюдать
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Lo
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %thingsboard · thingsboard15 дек. 2022 г.
- CVE-2020-2768735Наблюдать
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %thingsboard · thingsboard18 дек. 2020 г.
- CVE-2022-4834135Наблюдать
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %thingsboard · thingsboard23 февр. 2023 г.
- CVE-2022-4560835Наблюдать
An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %thingsboard · thingsboard1 мар. 2023 г.
- CVE-2023-4530335Наблюдать
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker sup
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %thingsboard · thingsboard6 окт. 2023 г.
- CVE-2023-2646232Наблюдать
ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege esc
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %thingsboard · thingsboard23 февр. 2023 г.
- CVE-2025-3428228Наблюдать
ThingsBoard < v4.2.1 SVG Image SSRF
СредняяCVSS 6,9Proof of conceptEPSS 2 %thingsboard · thingsboard17 окт. 2025 г.
- CVE-2024-327026Наблюдать
ThingsBoard AdvancedFeature access control
СредняяCVSS 6,5Эксплойта нетEPSS 1 %thingsboard · thingsboard3 апр. 2024 г.
- CVE-2024-5546626Наблюдать
An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1
СредняяCVSS 6,5Proof of conceptEPSS 0 %thingsboard · thingsboard12 мая 2025 г.
- CVE-2024-935824Наблюдать
ThingsBoard HTTP RPC API resource consumption
СредняяCVSS 6,0Эксплойта нетEPSS 1 %thingsboard · thingsboard30 сент. 2024 г.
- CVE-2025-3428124Наблюдать
Stored Cross-Site Scripting (XSS) in ThingsBoard
СредняяCVSS 6,2Эксплойта нетEPSS 0 %thingsboard · thingsboard17 окт. 2025 г.
- CVE-2022-3186121Наблюдать
Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %thingsboard · thingsboard13 сент. 2022 г.
- CVE-2021-4275020Наблюдать
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec
СредняяCVSS 4,8Proof of conceptEPSS 3 %thingsboard · thingsboard12 авг. 2022 г.
- CVE-2021-4275120Наблюдать
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec
СредняяCVSS 4,8Proof of conceptEPSS 3 %thingsboard · thingsboard12 авг. 2022 г.
- CVE-2025-90948Наблюдать
ThingsBoard Add Gateway special elements used in a template engine
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %thingsboard · thingsboard17 авг. 2025 г.