Alinto kayıtları
alinto üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-707 Improper Neutralization2
- CWE-184 Incomplete List of Disallowed Inputs1
- CWE-308 Use of Single-factor Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-399 Resource Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2015-5395İstismar yok | Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.debian · debian linux · CWE-352 | Yüksek8,8 | — | %0,9 | 20 Eyl 2017 |
27İzleyin | CVE-2016-6188İstismar yok | Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to uploadalinto · sogo · CWE-399 | Orta6,5 | — | %2,2 | 3 Şub 2017 |
24İzleyin | CVE-2014-9905İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web alinto · sogo · CWE-79 | Orta6,1 | — | %1,2 | 17 Şub 2017 |
24İzleyin | CVE-2016-6191İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackalinto · sogo · CWE-79 | Orta6,1 | — | %1,2 | 17 Şub 2017 |
24İzleyin | CVE-2023-48104Kavram kanıtı | Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.alinto · sogo · CWE-79 | Orta6,1 | — | %1,0 | 15 Oca 2024 |
24İzleyin | CVE-2022-4556Kavram kanıtı | Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scriptingalinto · sogo · CWE-707 | Orta6,1 | — | %0,6 | 16 Ara 2022 |
24İzleyin | CVE-2022-4558İstismar yok | Alinto SOGo Folder/Mail NSString+Utilities.m cross site scriptingalinto · sogo · CWE-707 | Orta6,1 | — | %0,6 | 16 Ara 2022 |
24İzleyin | CVE-2024-24510İstismar yok | Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function talinto · sogo · CWE-79 | Orta6,1 | — | %0,5 | 9 Eyl 2024 |
24İzleyin | CVE-2020-22402İstismar yok | Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reaalinto · sogo web mail · CWE-79 | Orta6,1 | — | %0,4 | 14 Haz 2023 |
24İzleyin | CVE-2024-34462İstismar yok | Alinto SOGo through 5.10.0 allows XSS during attachment preview.alinto · sogo · CWE-79 | Orta6,1 | — | %0,3 | 4 May 2024 |
24İzleyin | CVE-2025-63499Kavram kanıtı | Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.alinto · sogo · CWE-79 | Orta6,1 | — | %0,3 | 4 Ara 2025 |
24İzleyin | CVE-2025-63498Kavram kanıtı | alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.alinto · sogo · CWE-79 | Orta6,1 | — | %0,3 | 24 Kas 2025 |
24İzleyin | CVE-2025-71276İstismar yok | SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.alinto · sogo · CWE-79 | Orta6,1 | — | %0,1 | 21 Mar 2026 |
17İzleyin | CVE-2016-6189İstismar yok | Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by readingalinto · sogo · CWE-184 | Orta4,3 | — | %1,4 | 17 Şub 2017 |
10İzleyin | CVE-2026-33550İstismar yok | SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommalinto · sogo · CWE-308 | Düşük2,6 | — | %0,2 | 21 Mar 2026 |
8İzleyin | CVE-2026-3054İstismar yok | Alinto SOGo cross site scriptingalinto · sogo · CWE-79 | Düşük2,1 | — | %0,5 | 23 Şub 2026 |
- CVE-2015-539535İzleyin
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
YüksekCVSS 8,8İstismar yokEPSS %1debian · debian linux20 Eyl 2017
- CVE-2016-618827İzleyin
Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload
OrtaCVSS 6,5İstismar yokEPSS %2alinto · sogo3 Şub 2017
- CVE-2014-990524İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web
OrtaCVSS 6,1İstismar yokEPSS %1alinto · sogo17 Şub 2017
- CVE-2016-619124İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attack
OrtaCVSS 6,1İstismar yokEPSS %1alinto · sogo17 Şub 2017
- CVE-2023-4810424İzleyin
Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.
OrtaCVSS 6,1Kavram kanıtıEPSS %1alinto · sogo15 Oca 2024
- CVE-2022-455624İzleyin
Alinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scripting
OrtaCVSS 6,1Kavram kanıtıEPSS %1alinto · sogo16 Ara 2022
- CVE-2022-455824İzleyin
Alinto SOGo Folder/Mail NSString+Utilities.m cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1alinto · sogo16 Ara 2022
- CVE-2024-2451024İzleyin
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function t
OrtaCVSS 6,1İstismar yokEPSS %0alinto · sogo9 Eyl 2024
- CVE-2020-2240224İzleyin
Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user rea
OrtaCVSS 6,1İstismar yokEPSS %0alinto · sogo web mail14 Haz 2023
- CVE-2024-3446224İzleyin
Alinto SOGo through 5.10.0 allows XSS during attachment preview.
OrtaCVSS 6,1İstismar yokEPSS %0alinto · sogo4 May 2024
- CVE-2025-6349924İzleyin
Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %0alinto · sogo4 Ara 2025
- CVE-2025-6349824İzleyin
alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %0alinto · sogo24 Kas 2025
- CVE-2025-7127624İzleyin
SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
OrtaCVSS 6,1İstismar yokEPSS %0alinto · sogo21 Mar 2026
- CVE-2016-618917İzleyin
Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading
OrtaCVSS 4,3İstismar yokEPSS %1alinto · sogo17 Şub 2017
- CVE-2026-3355010İzleyin
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recomm
DüşükCVSS 2,6İstismar yokEPSS %0alinto · sogo21 Mar 2026
- CVE-2026-30548İzleyin
Alinto SOGo cross site scripting
DüşükCVSS 2,1İstismar yokEPSS %0alinto · sogo23 Şub 2026