aimeos kayıtları
aimeos üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-270 Privilege Context Switching Error1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-73 External Control of File Name or Path1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-841 Improper Enforcement of Behavioral Workflow1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
28İzleyin | CVE-2024-37295İstismar yok | Aimeos Core remote code execution in web server contextaimeos · aimeos-core · CWE-73 | Yüksek7,2 | — | %0,6 | 11 Haz 2024 |
24İzleyin | CVE-2025-66468İstismar yok | Aimeos GrapesJS CMS extension possible stores XSS exploitable by authenticated editorsaimeos · grapesjs cms · CWE-79 | Orta6,1 | — | %0,3 | 2 Ara 2025 |
22İzleyin | CVE-2024-37294İstismar yok | Aimeos denial of service vulnerability in SaaS and marketplace setupsaimeos · aimeos-core · CWE-270 | Orta5,5 | — | %0,4 | 11 Haz 2024 |
21İzleyin | CVE-2024-39319İstismar yok | aimeos/ai-controller-frontend has IDOR vulnerability in account profile pageaimeos · aimeos frontend controller · CWE-639 | Orta5,3 | — | %0,5 | 26 Eyl 2024 |
21İzleyin | CVE-2024-39325İstismar yok | aimeos/ai-controller-frontend doesn't reset payment status in basketaimeos · aimeos frontend controller · CWE-841 | Orta5,3 | — | %0,4 | 2 Tem 2024 |
15İzleyin | CVE-2024-39324İstismar yok | aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own servicesaimeos · ai-admin-graphql · CWE-863 | Düşük3,8 | — | %0,4 | 2 Tem 2024 |
- CVE-2024-3729528İzleyin
Aimeos Core remote code execution in web server context
YüksekCVSS 7,2İstismar yokEPSS %1aimeos · aimeos-core11 Haz 2024
- CVE-2025-6646824İzleyin
Aimeos GrapesJS CMS extension possible stores XSS exploitable by authenticated editors
OrtaCVSS 6,1İstismar yokEPSS %0aimeos · grapesjs cms2 Ara 2025
- CVE-2024-3729422İzleyin
Aimeos denial of service vulnerability in SaaS and marketplace setups
OrtaCVSS 5,5İstismar yokEPSS %0aimeos · aimeos-core11 Haz 2024
- CVE-2024-3931921İzleyin
aimeos/ai-controller-frontend has IDOR vulnerability in account profile page
OrtaCVSS 5,3İstismar yokEPSS %0aimeos · aimeos frontend controller26 Eyl 2024
- CVE-2024-3932521İzleyin
aimeos/ai-controller-frontend doesn't reset payment status in basket
OrtaCVSS 5,3İstismar yokEPSS %0aimeos · aimeos frontend controller2 Tem 2024
- CVE-2024-3932415İzleyin
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
DüşükCVSS 3,8İstismar yokEPSS %0aimeos · ai-admin-graphql2 Tem 2024