Sina Kheirkhah (SinSinology)
watchTowr (watchTowrcyber)
37 kredili kayıt · son 12 ayda 7 · 5 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
29İzleyin | CVE-2026-19590İstismar yok | OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repositoopenai · codex desktop · CWE-427 | Yüksek7,3 | — | %0,1 | 1 Eyl 2026 |
34İzleyin | CVE-2026-65690İstismar yok | Bold Reports Standalone Report Designer < 14.1.12 Path Traversal RCE via File Uploadsyncfusion · standalone report designer · CWE-22 | Yüksek8,7 | — | %0,9 | 23 Tem 2026 |
37İzleyin | CVE-2026-65689İstismar yok | Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database Downloadsyncfusion · standalone report designer · CWE-22 | Kritik9,3 | — | %0,9 | 23 Tem 2026 |
37İzleyin | CVE-2026-65688İstismar yok | Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font Processingsyncfusion · standalone report designer · CWE-22 | Kritik9,3 | — | %0,9 | 23 Tem 2026 |
37İzleyin | CVE-2026-65687İstismar yok | Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG Processingsyncfusion · standalone report designer · CWE-22 | Kritik9,3 | — | %0,9 | 23 Tem 2026 |
30İzleyin | CVE-2025-14713İstismar yok | An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote atsynology · c2 identity edge server · CWE-749 | Yüksek7,5 | — | %0,5 | 27 May 2026 |
27İzleyin | CVE-2026-0932İstismar yok | Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server befom-files · m-files server · CWE-918 | Orta6,9 | — | %0,2 | 1 Nis 2026 |
35İzleyin | CVE-2025-7433İstismar yok | A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and older allows arbitrarsophos · sophos intercept x for windows · CWE-502 | Yüksek8,8 | — | %0,1 | 17 Tem 2025 |
35İzleyin | CVE-2025-25271İstismar yok | OCPP Backend Configuration via Insecure Defaultsphoenixcontact · charx sec-3000 firmware · CWE-1188 | Yüksek8,8 | — | %0,3 | 8 Tem 2025 |
61Bu hafta | CVE-2025-2777Kavram kanıtı | SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | Kritik9,8 | — | %72,2 | 7 May 2025 |
88Hemen | CVE-2025-2776Silahlaştırılmış | SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | Kritik9,8 | KEV | %64,4 | 7 May 2025 |
73Bu hafta | CVE-2025-2775Silahlaştırılmış | SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | Yüksek7,5 | KEV | %43,0 | 7 May 2025 |
36İzleyin | CVE-2024-46908İstismar yok | WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation Vulnerabilityprogress · whatsup gold · CWE-89 | Yüksek8,8 | — | %2,2 | 2 Ara 2024 |
36İzleyin | CVE-2024-46907İstismar yok | WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation Vulnerabilityprogress · whatsup gold · CWE-89 | Yüksek8,8 | — | %2,2 | 2 Ara 2024 |
47Planlayın | CVE-2024-46906İstismar yok | WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerabilityprogress · whatsup gold · CWE-89 | Yüksek8,8 | — | %40,4 | 2 Ara 2024 |
36İzleyin | CVE-2024-46905İstismar yok | WhatsUp Gold GetOrderByClause SQL Injection Privilege Escalation Vulnerabilityprogress · whatsup gold · CWE-89 | Yüksek8,8 | — | %2,2 | 2 Ara 2024 |
30İzleyin | CVE-2024-7763İstismar yok | WhatsUp Gold getReport Missing Authentication Authentication Bypass Vulnerabilityprogress · whatsup gold · CWE-287 | Yüksek7,5 | — | %0,6 | 24 Eki 2024 |
35İzleyin | CVE-2024-8885İstismar yok | A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writinsophos · sophos intercept x · CWE-502 | Yüksek8,8 | — | %0,1 | 2 Eki 2024 |
35İzleyin | CVE-2024-6672İstismar yok | WhatsUp Gold getMonitorJoin SQL Injection Privilege Escalation Vulnerabilityprogress · whatsup gold · CWE-89 | Yüksek8,8 | — | %0,7 | 29 Ağu 2024 |
45Planlayın | CVE-2024-6671Kavram kanıtı | WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerabilityprogress · whatsup gold · CWE-89 | Kritik9,8 | — | %19,0 | 29 Ağu 2024 |
97Hemen | CVE-2024-6670Silahlaştırılmış | WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerabilityprogress · whatsup gold · CWE-89 | Kritik9,8 | KEV | %93,0 | 29 Ağu 2024 |
30İzleyin | CVE-2024-5019İstismar yok | WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerabilityprogress · whatsup gold · CWE-22 | Yüksek7,5 | — | %0,8 | 25 Haz 2024 |
35İzleyin | CVE-2024-5016İstismar yok | WhatsUp Gold OnMessage Deserialization of Untrusted Data Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-502 | Yüksek7,2 | — | %22,4 | 25 Haz 2024 |
35İzleyin | CVE-2024-5015İstismar yok | WhatsUp Gold SessionControler Server-Side Request Forgery Information Disclosure Vulnerabilityprogress · whatsup gold · CWE-918 | Yüksek8,8 | — | %0,5 | 25 Haz 2024 |
30İzleyin | CVE-2024-5013İstismar yok | WhatsUp Gold InstallController Denial-of-Service Vulnerabilityprogress · whatsup gold · CWE-400 | Yüksek7,5 | — | %0,8 | 25 Haz 2024 |
- CVE-2026-1959029İzleyin
OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the reposito
YüksekCVSS 7,3İstismar yokEPSS %0openai · codex desktop1 Eyl 2026
- CVE-2026-6569034İzleyin
Bold Reports Standalone Report Designer < 14.1.12 Path Traversal RCE via File Upload
YüksekCVSS 8,7İstismar yokEPSS %1syncfusion · standalone report designer23 Tem 2026
- CVE-2026-6568937İzleyin
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database Download
KritikCVSS 9,3İstismar yokEPSS %1syncfusion · standalone report designer23 Tem 2026
- CVE-2026-6568837İzleyin
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font Processing
KritikCVSS 9,3İstismar yokEPSS %1syncfusion · standalone report designer23 Tem 2026
- CVE-2026-6568737İzleyin
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG Processing
KritikCVSS 9,3İstismar yokEPSS %1syncfusion · standalone report designer23 Tem 2026
- CVE-2025-1471330İzleyin
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote at
YüksekCVSS 7,5İstismar yokEPSS %0synology · c2 identity edge server27 May 2026
- CVE-2026-093227İzleyin
Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server befo
OrtaCVSS 6,9İstismar yokEPSS %0m-files · m-files server1 Nis 2026
- CVE-2025-743335İzleyin
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and older allows arbitrar
YüksekCVSS 8,8İstismar yokEPSS %0sophos · sophos intercept x for windows17 Tem 2025
- CVE-2025-2527135İzleyin
OCPP Backend Configuration via Insecure Defaults
YüksekCVSS 8,8İstismar yokEPSS %0phoenixcontact · charx sec-3000 firmware8 Tem 2025
- CVE-2025-277761Bu hafta
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
KritikCVSS 9,8Kavram kanıtıEPSS %72sysaid · sysaid7 May 2025
- CVE-2025-277688Hemen
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %64sysaid · sysaid7 May 2025
- CVE-2025-277573Bu hafta
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %43sysaid · sysaid7 May 2025
- CVE-2024-4690836İzleyin
WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2progress · whatsup gold2 Ara 2024
- CVE-2024-4690736İzleyin
WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2progress · whatsup gold2 Ara 2024
- CVE-2024-4690647Planlayın
WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %40progress · whatsup gold2 Ara 2024
- CVE-2024-4690536İzleyin
WhatsUp Gold GetOrderByClause SQL Injection Privilege Escalation Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2progress · whatsup gold2 Ara 2024
- CVE-2024-776330İzleyin
WhatsUp Gold getReport Missing Authentication Authentication Bypass Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1progress · whatsup gold24 Eki 2024
- CVE-2024-888535İzleyin
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writin
YüksekCVSS 8,8İstismar yokEPSS %0sophos · sophos intercept x2 Eki 2024
- CVE-2024-667235İzleyin
WhatsUp Gold getMonitorJoin SQL Injection Privilege Escalation Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1progress · whatsup gold29 Ağu 2024
- CVE-2024-667145Planlayın
WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %19progress · whatsup gold29 Ağu 2024
- CVE-2024-667097Hemen
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %93progress · whatsup gold29 Ağu 2024
- CVE-2024-501930İzleyin
WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1progress · whatsup gold25 Haz 2024
- CVE-2024-501635İzleyin
WhatsUp Gold OnMessage Deserialization of Untrusted Data Remote Code Execution Vulnerability
YüksekCVSS 7,2İstismar yokEPSS %22progress · whatsup gold25 Haz 2024
- CVE-2024-501535İzleyin
WhatsUp Gold SessionControler Server-Side Request Forgery Information Disclosure Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1progress · whatsup gold25 Haz 2024
- CVE-2024-501330İzleyin
WhatsUp Gold InstallController Denial-of-Service Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1progress · whatsup gold25 Haz 2024