abbyy kayıtları
abbyy üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2018-13791İstismar yok | The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12abbyy · flexicapture · CWE-732 | Kritik9,8 | — | %1,1 | 9 Tem 2018 |
39İzleyin | CVE-2018-13792İstismar yok | Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attackerabbyy · flexicapture · CWE-89 | Kritik9,8 | — | %1,0 | 9 Şub 2019 |
35İzleyin | CVE-2018-13793İstismar yok | Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 exist in Web Vabbyy · flexicapture · CWE-352 | Yüksek8,8 | — | %0,5 | 9 Tem 2018 |
31İzleyin | CVE-2019-20383İstismar yok | ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via abbyy · finereader · CWE-59 | Yüksek7,8 | — | %0,5 | 13 Ağu 2020 |
- CVE-2018-1379139İzleyin
The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12
KritikCVSS 9,8İstismar yokEPSS %1abbyy · flexicapture9 Tem 2018
- CVE-2018-1379239İzleyin
Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker
KritikCVSS 9,8İstismar yokEPSS %1abbyy · flexicapture9 Şub 2019
- CVE-2018-1379335İzleyin
Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 exist in Web V
YüksekCVSS 8,8İstismar yokEPSS %0abbyy · flexicapture9 Tem 2018
- CVE-2019-2038331İzleyin
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via
YüksekCVSS 7,8İstismar yokEPSS %0abbyy · finereader13 Ağu 2020