Записи Zend
46 опубликованных записей вендора zend.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 56,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-20 Improper Input Validation2
- CWE-287 Improper Authentication2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
46 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2021-3007Proof of concept | Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execuzend · zend framework · CWE-502 | Критическая9,8 | — | 75,3 % | 3 янв. 2021 г. |
51В плане | CVE-2012-3363Proof of concept | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows rezend · zend framework · CWE-611 | Критическая9,1 | — | 50,2 % | 13 февр. 2013 г. |
51В плане | CVE-2016-10034Proof of concept | The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framewzend · zend framework · CWE-77 | Критическая9,8 | — | 38,4 % | 30 дек. 2016 г. |
40В плане | CVE-2016-4861Proof of concept | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injeczend · zend framework · CWE-89 | Критическая9,8 | — | 4,1 % | 16 февр. 2017 г. |
40В плане | CVE-2011-1939Proof of concept | SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conzend · zend framework · CWE-89 | Критическая9,8 | — | 3,9 % | 26 нояб. 2019 г. |
40В плане | CVE-2015-7695Эксплойта нет | The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrzend · zend framework · CWE-89 | Критическая9,8 | — | 3,0 % | 7 июн. 2016 г. |
40В плане | CVE-2014-8089Эксплойта нет | SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extensionzend · zend framework · CWE-89 | Критическая9,8 | — | 2,6 % | 17 февр. 2020 г. |
40В плане | CVE-2014-4914Эксплойта нет | The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to cozend · zend framework · CWE-89 | Критическая9,8 | — | 2,3 % | 29 дек. 2017 г. |
40В плане | CVE-2016-6233Эксплойта нет | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injeczend · zend framework · CWE-89 | Критическая9,8 | — | 2,0 % | 16 февр. 2017 г. |
39Наблюдать | CVE-2020-8986Эксплойта нет | lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attazend · zendto · CWE-754 | Критическая9,8 | — | 1,5 % | 24 мар. 2020 г. |
39Наблюдать | CVE-2020-29312Эксплойта нет | An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function.zend · zend framework · CWE-502 | Критическая9,8 | — | 1,3 % | 4 апр. 2023 г. |
39Наблюдать | CVE-2015-0270Эксплойта нет | Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.zend · framework · CWE-89 | Критическая9,8 | — | 1,1 % | 25 окт. 2019 г. |
37Наблюдать | CVE-2024-9129Эксплойта нет | Format String Injection in Zend Serverzend · zend server · CWE-134 | Критическая9,3 | — | 0,4 % | 22 окт. 2024 г. |
36Наблюдать | CVE-2015-1555Эксплойта нет | Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions withouzend · zend framework · CWE-20 | Критическая9,1 | — | 1,4 % | 7 авг. 2017 г. |
35Наблюдать | CVE-2015-1786Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token idenzend · zend framework · CWE-352 | Высокая8,8 | — | 0,7 % | 8 июн. 2017 г. |
35Наблюдать | CVE-2020-8985Эксплойта нет | ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.zend · zendto · CWE-79 | Высокая8,8 | — | 0,5 % | 24 мар. 2020 г. |
31Наблюдать | CVE-2006-4431Эксплойта нет | Multiple buffer overflows in the (a) Session Clustering Daemon and the (b) mod_cluster module in the Zend Platform 2.2.1 and earlier allow rzend · zend platform · CWE-119 | Высокая7,5 | — | 4,6 % | 28 авг. 2006 г. |
31Наблюдать | CVE-2014-2685Эксплойта нет | The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 beforezend · zend framework · CWE-287 | Высокая7,5 | — | 2,8 % | 4 сент. 2014 г. |
31Наблюдать | CVE-2006-4432Эксплойта нет | Directory traversal vulnerability in Zend Platform 2.2.1 and earlier allows remote attackers to overwrite arbitrary files via a ..zend · zend platform | Высокая7,5 | — | 2,1 % | 28 авг. 2006 г. |
31Наблюдать | CVE-2015-5723Эксплойта нет | Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 ozend · zend-cache · CWE-264 | Высокая7,8 | — | 0,4 % | 7 июн. 2016 г. |
30Наблюдать | CVE-2015-5161Proof of concept | The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when runninzend · zend framework | Средняя6,8 | — | 9,9 % | 25 авг. 2015 г. |
30Наблюдать | CVE-2015-7503Эксплойта нет | Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSAzend · zend framework · CWE-320 | Высокая7,5 | — | 1,4 % | 10 окт. 2017 г. |
30Наблюдать | CVE-2020-8984Эксплойта нет | lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.zend · zendto · CWE-346 | Высокая7,5 | — | 0,5 % | 24 мар. 2020 г. |
28Наблюдать | CVE-2014-2682Эксплойта нет | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobblerzend · zendrest · CWE-19 | Средняя6,8 | — | 2,2 % | 15 нояб. 2014 г. |
27Наблюдать | CVE-2006-5900Эксплойта нет | Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview zend · zend framework preview | Средняя6,8 | — | 1,2 % | 15 нояб. 2006 г. |
- CVE-2021-300762На этой неделе
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execu
КритическаяCVSS 9,8Proof of conceptEPSS 75 %zend · zend framework3 янв. 2021 г.
- CVE-2012-336351В плане
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows re
КритическаяCVSS 9,1Proof of conceptEPSS 50 %zend · zend framework13 февр. 2013 г.
- CVE-2016-1003451В плане
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framew
КритическаяCVSS 9,8Proof of conceptEPSS 38 %zend · zend framework30 дек. 2016 г.
- CVE-2016-486140В плане
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injec
КритическаяCVSS 9,8Proof of conceptEPSS 4 %zend · zend framework16 февр. 2017 г.
- CVE-2011-193940В плане
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in con
КритическаяCVSS 9,8Proof of conceptEPSS 4 %zend · zend framework26 нояб. 2019 г.
- CVE-2015-769540В плане
The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitr
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %zend · zend framework7 июн. 2016 г.
- CVE-2014-808940В плане
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %zend · zend framework17 февр. 2020 г.
- CVE-2014-491440В плане
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to co
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zend · zend framework29 дек. 2017 г.
- CVE-2016-623340В плане
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injec
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zend · zend framework16 февр. 2017 г.
- CVE-2020-898639Наблюдать
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an atta
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %zend · zendto24 мар. 2020 г.
- CVE-2020-2931239Наблюдать
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zend · zend framework4 апр. 2023 г.
- CVE-2015-027039Наблюдать
Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zend · framework25 окт. 2019 г.
- CVE-2024-912937Наблюдать
Format String Injection in Zend Server
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %zend · zend server22 окт. 2024 г.
- CVE-2015-155536Наблюдать
Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions withou
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %zend · zend framework7 авг. 2017 г.
- CVE-2015-178635Наблюдать
Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token iden
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %zend · zend framework8 июн. 2017 г.
- CVE-2020-898535Наблюдать
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %zend · zendto24 мар. 2020 г.
- CVE-2006-443131Наблюдать
Multiple buffer overflows in the (a) Session Clustering Daemon and the (b) mod_cluster module in the Zend Platform 2.2.1 and earlier allow r
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %zend · zend platform28 авг. 2006 г.
- CVE-2014-268531Наблюдать
The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %zend · zend framework4 сент. 2014 г.
- CVE-2006-443231Наблюдать
Directory traversal vulnerability in Zend Platform 2.2.1 and earlier allows remote attackers to overwrite arbitrary files via a ..
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %zend · zend platform28 авг. 2006 г.
- CVE-2015-572331Наблюдать
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 o
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %zend · zend-cache7 июн. 2016 г.
- CVE-2015-516130Наблюдать
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when runnin
СредняяCVSS 6,8Proof of conceptEPSS 10 %zend · zend framework25 авг. 2015 г.
- CVE-2015-750330Наблюдать
Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %zend · zend framework10 окт. 2017 г.
- CVE-2020-898430Наблюдать
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %zend · zendto24 мар. 2020 г.
- CVE-2014-268228Наблюдать
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler
СредняяCVSS 6,8Эксплойта нетEPSS 2 %zend · zendrest15 нояб. 2014 г.
- CVE-2006-590027Наблюдать
Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview
СредняяCVSS 6,8Эксплойта нетEPSS 1 %zend · zend framework preview15 нояб. 2006 г.