Piotr Bazydlo (@chudyPB)
watchTowr
73 kredili kayıt · son 12 ayda 7 · 1 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
29İzleyin | CVE-2026-82077İstismar yok | PaperCut NG/MF: Remote Code Execution via Scan2Faxpapercut · papercut ng/mf · CWE-22 | Yüksek7,3 | — | %0,7 | 5 gün önce |
28İzleyin | CVE-2026-16137İstismar yok | Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controllerprogress · sharefile storage zones controller · CWE-22 | Yüksek7,2 | — | %0,7 | 17 Ağu 2026 |
37İzleyin | CVE-2026-26339İstismar yok | Hyland Alfresco Transformation Service Argument Injection RCEhyland · alfresco transform service · CWE-918 | Kritik9,3 | — | %1,1 | 19 Şub 2026 |
27İzleyin | CVE-2026-26338İstismar yok | Hyland Alfresco Transformation Service SSRFhyland · alfresco transform service · CWE-918 | Orta6,9 | — | %0,7 | 19 Şub 2026 |
35İzleyin | CVE-2026-26337İstismar yok | Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and SSRFhyland · alfresco transform service · CWE-36 | Yüksek8,8 | — | %0,5 | 19 Şub 2026 |
34İzleyin | CVE-2026-26336Kavram kanıtı | Hyland Alfresco Improper Authorization Arbitrary File Readhyland · alfresco content services · CWE-863 | Yüksek8,7 | — | %0,7 | 19 Şub 2026 |
20İzleyin | CVE-2026-0601İstismar yok | Nexus Repository 3 - Cross-Site Scriptingsonatype · nexus repository · CWE-79 | Orta5,1 | — | %0,4 | 14 Oca 2026 |
37İzleyin | CVE-2025-3600İstismar yok | Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAXprogress · telerik ui for asp.net ajax · CWE-470 | Yüksek7,5 | — | %24,1 | 14 May 2025 |
39İzleyin | CVE-2025-32370Kavram kanıtı | Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, becauskentico · xperience · CWE-912 | Kritik9,8 | — | %1,5 | 6 Nis 2025 |
21İzleyin | CVE-2025-32369İstismar yok | Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with kentico · xperience · CWE-79 | Orta5,4 | — | %0,3 | 6 Nis 2025 |
33İzleyin | CVE-2024-28991İstismar yok | SolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code Executionsolarwinds · access rights manager · CWE-502 | Yüksek8,0 | — | %3,1 | 12 Eyl 2024 |
35İzleyin | CVE-2024-28990İstismar yok | SolarWinds Access Rights Manager (ARM) Hardcoded Credentials Authentication Bypass Vulnerabilitysolarwinds · access rights manager · CWE-798 | Yüksek8,8 | — | %0,5 | 12 Eyl 2024 |
33İzleyin | CVE-2024-28993İstismar yok | SolarWinds Access Rights Manager Directory Traversal and Information Disclosure Vulnerabilitysolarwinds · access rights manager · CWE-22 | Yüksek8,3 | — | %1,0 | 17 Tem 2024 |
34İzleyin | CVE-2024-28992İstismar yok | SolarWinds Access Rights Manager Directory Traversal and Information Disclosure Vulnerabilitysolarwinds · access rights manager · CWE-287 | Yüksek8,3 | — | %1,9 | 17 Tem 2024 |
36İzleyin | CVE-2024-23475İstismar yok | SolarWinds Access Rights Manager Directory Traversal and Information Disclosure Vulnerabilitysolarwinds · access rights manager · CWE-22 | Yüksek8,8 | — | %2,1 | 17 Tem 2024 |
35İzleyin | CVE-2024-23474İstismar yok | SolarWinds Access Rights Manager (ARM) deleteTransferFile Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerabilitysolarwinds · access rights manager · CWE-22 | Yüksek8,8 | — | %1,5 | 17 Tem 2024 |
38İzleyin | CVE-2024-23472İstismar yok | SolarWinds Access Rights Manager Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerabilitysolarwinds · access rights manager · CWE-22 | Yüksek8,0 | — | %18,6 | 17 Tem 2024 |
40Planlayın | CVE-2024-23469İstismar yok | SolarWinds Access Rights Manager Exposed Dangerous Method Remote Code Execution Vulnerabilitysolarwinds · access rights manager · CWE-20 | Yüksek8,8 | — | %17,9 | 17 Tem 2024 |
34İzleyin | CVE-2024-23468İstismar yok | SolarWinds Access Rights Manager Directory Traversal and Information Disclosure Vulnerabilitysolarwinds · access rights manager · CWE-22 | Yüksek8,3 | — | %3,4 | 17 Tem 2024 |
36İzleyin | CVE-2024-23465İstismar yok | SolarWinds Access Rights Manager (ARM) ChangeHumster Exposed Dangerous Method Authentication Bypass Vulnerabilitysolarwinds · access rights manager · CWE-287 | Yüksek8,8 | — | %1,9 | 17 Tem 2024 |
55Planlayın | CVE-2024-28075İstismar yok | SolarWinds ARM Deserialization of Untrusted Data Remote Code Executionsolarwinds · access rights manager · CWE-502 | Yüksek8,0 | — | %78,0 | 14 May 2024 |
39İzleyin | CVE-2024-23473İstismar yok | SolarWinds Access Rights Manager (ARM) Hard-Coded Credentials Authentication Bypass Vulnerabilitysolarwinds · access rights manager · CWE-798 | Kritik9,8 | — | %1,1 | 14 May 2024 |
56Planlayın | CVE-2024-23478İstismar yok | SolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code Executionsolarwinds · access rights manager · CWE-502 | Yüksek8,0 | — | %81,6 | 15 Şub 2024 |
32İzleyin | CVE-2023-50395İstismar yok | SQL Injection Remote Code Execution Vulnerabilitysolarwinds · solarwinds platform · CWE-89 | Yüksek8,0 | — | %1,6 | 6 Şub 2024 |
32İzleyin | CVE-2023-35188İstismar yok | SQL Injection Remote Code Execution Vulnerabilitysolarwinds · solarwinds platform · CWE-89 | Yüksek8,0 | — | %1,5 | 6 Şub 2024 |
- CVE-2026-8207729İzleyin
PaperCut NG/MF: Remote Code Execution via Scan2Fax
YüksekCVSS 7,3İstismar yokEPSS %1papercut · papercut ng/mf5 gün önce
- CVE-2026-1613728İzleyin
Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller
YüksekCVSS 7,2İstismar yokEPSS %1progress · sharefile storage zones controller17 Ağu 2026
- CVE-2026-2633937İzleyin
Hyland Alfresco Transformation Service Argument Injection RCE
KritikCVSS 9,3İstismar yokEPSS %1hyland · alfresco transform service19 Şub 2026
- CVE-2026-2633827İzleyin
Hyland Alfresco Transformation Service SSRF
OrtaCVSS 6,9İstismar yokEPSS %1hyland · alfresco transform service19 Şub 2026
- CVE-2026-2633735İzleyin
Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and SSRF
YüksekCVSS 8,8İstismar yokEPSS %1hyland · alfresco transform service19 Şub 2026
- CVE-2026-2633634İzleyin
Hyland Alfresco Improper Authorization Arbitrary File Read
YüksekCVSS 8,7Kavram kanıtıEPSS %1hyland · alfresco content services19 Şub 2026
- CVE-2026-060120İzleyin
Nexus Repository 3 - Cross-Site Scripting
OrtaCVSS 5,1İstismar yokEPSS %0sonatype · nexus repository14 Oca 2026
- CVE-2025-360037İzleyin
Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX
YüksekCVSS 7,5İstismar yokEPSS %24progress · telerik ui for asp.net ajax14 May 2025
- CVE-2025-3237039İzleyin
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, becaus
KritikCVSS 9,8Kavram kanıtıEPSS %2kentico · xperience6 Nis 2025
- CVE-2025-3236921İzleyin
Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with
OrtaCVSS 5,4İstismar yokEPSS %0kentico · xperience6 Nis 2025
- CVE-2024-2899133İzleyin
SolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code Execution
YüksekCVSS 8,0İstismar yokEPSS %3solarwinds · access rights manager12 Eyl 2024
- CVE-2024-2899035İzleyin
SolarWinds Access Rights Manager (ARM) Hardcoded Credentials Authentication Bypass Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0solarwinds · access rights manager12 Eyl 2024
- CVE-2024-2899333İzleyin
SolarWinds Access Rights Manager Directory Traversal and Information Disclosure Vulnerability
YüksekCVSS 8,3İstismar yokEPSS %1solarwinds · access rights manager17 Tem 2024
- CVE-2024-2899234İzleyin
SolarWinds Access Rights Manager Directory Traversal and Information Disclosure Vulnerability
YüksekCVSS 8,3İstismar yokEPSS %2solarwinds · access rights manager17 Tem 2024
- CVE-2024-2347536İzleyin
SolarWinds Access Rights Manager Directory Traversal and Information Disclosure Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2solarwinds · access rights manager17 Tem 2024
- CVE-2024-2347435İzleyin
SolarWinds Access Rights Manager (ARM) deleteTransferFile Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2solarwinds · access rights manager17 Tem 2024
- CVE-2024-2347238İzleyin
SolarWinds Access Rights Manager Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
YüksekCVSS 8,0İstismar yokEPSS %19solarwinds · access rights manager17 Tem 2024
- CVE-2024-2346940Planlayın
SolarWinds Access Rights Manager Exposed Dangerous Method Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %18solarwinds · access rights manager17 Tem 2024
- CVE-2024-2346834İzleyin
SolarWinds Access Rights Manager Directory Traversal and Information Disclosure Vulnerability
YüksekCVSS 8,3İstismar yokEPSS %3solarwinds · access rights manager17 Tem 2024
- CVE-2024-2346536İzleyin
SolarWinds Access Rights Manager (ARM) ChangeHumster Exposed Dangerous Method Authentication Bypass Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2solarwinds · access rights manager17 Tem 2024
- CVE-2024-2807555Planlayın
SolarWinds ARM Deserialization of Untrusted Data Remote Code Execution
YüksekCVSS 8,0İstismar yokEPSS %78solarwinds · access rights manager14 May 2024
- CVE-2024-2347339İzleyin
SolarWinds Access Rights Manager (ARM) Hard-Coded Credentials Authentication Bypass Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1solarwinds · access rights manager14 May 2024
- CVE-2024-2347856Planlayın
SolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code Execution
YüksekCVSS 8,0İstismar yokEPSS %82solarwinds · access rights manager15 Şub 2024
- CVE-2023-5039532İzleyin
SQL Injection Remote Code Execution Vulnerability
YüksekCVSS 8,0İstismar yokEPSS %2solarwinds · solarwinds platform6 Şub 2024
- CVE-2023-3518832İzleyin
SQL Injection Remote Code Execution Vulnerability
YüksekCVSS 8,0İstismar yokEPSS %2solarwinds · solarwinds platform6 Şub 2024