İçeriğe atla
Noroxi

bladex kayıtları

bladex üreticisine ait 9 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

  1. 20
  2. 22
  3. 23
  4. 24
  5. 26

Çubuk: toplam · koyu kısım: CISA KEV.

Tüm kayıtlar

9 kayıt
  • CVE-2023-40787
    44Planlayın

    In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL

    KritikCVSS 9,8İstismar yokEPSS %18

    bladex · springblade29 Ağu 2023

  • CVE-2022-27360
    40Planlayın

    SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.

    KritikCVSS 9,8İstismar yokEPSS %2

    bladex · springblade5 May 2022

  • CVE-2020-16165
    39İzleyin

    The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause.

    KritikCVSS 9,8İstismar yokEPSS %1

    bladex · springblade30 Tem 2020

  • CVE-2023-47458
    39İzleyin

    An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.

    KritikCVSS 9,8İstismar yokEPSS %1

    bladex · springblade2 Oca 2024

  • CVE-2025-70983
    39İzleyin

    Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

    KritikCVSS 9,9İstismar yokEPSS %0

    bladex · springblade23 Oca 2026

  • CVE-2025-70982
    39İzleyin

    Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import s

    KritikCVSS 9,9İstismar yokEPSS %0

    bladex · springblade26 Oca 2026

  • CVE-2024-33332
    30İzleyin

    An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant

    YüksekCVSS 7,5İstismar yokEPSS %1

    bladex · springblade30 Nis 2024

  • CVE-2023-40788
    21İzleyin

    SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthoriz

    OrtaCVSS 5,3İstismar yokEPSS %1

    bladex · springblade18 Eyl 2023

  • CVE-2024-8023
    21İzleyin

    chillzhuang SpringBlade list sql injection

    OrtaCVSS 5,3İstismar yokEPSS %1

    bladex · springblade20 Ağu 2024