canto kayıtları
canto üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-918 Server-Side Request Forgery (SSRF)5
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2023-3452Kavram kanıtı | Canto <= 3.0.4 - Unauthenticated Remote File Inclusioncanto · canto · CWE-98 | Kritik9,8 | — | %7,0 | 11 Ağu 2023 |
39İzleyin | CVE-2022-40305İstismar yok | A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network rescanto · canto · CWE-918 | Kritik9,8 | — | %1,5 | 9 Eyl 2022 |
39İzleyin | CVE-2024-4936İstismar yok | Canto <= 3.0.8 - Unauthenticated Remote File Inclusioncanto · canto · CWE-98 | Kritik9,8 | — | %1,0 | 14 Haz 2024 |
39İzleyin | CVE-2024-25096Kavram kanıtı | WordPress canto plugin <= 3.0.7 - Unauth. Remote Code Execution (RCE) vulnerabilitycanto · canto · CWE-94 | Kritik9,8 | — | %0,7 | 3 Nis 2024 |
31İzleyin | CVE-2013-7416İstismar yok | canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a canto · canto curses · CWE-77 | Yüksek7,5 | — | %2,8 | 3 Ara 2014 |
29İzleyin | CVE-2020-28976Kavram kanıtı | The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability.canto · canto · CWE-918 | Orta5,3 | — | %27,8 | 30 Kas 2020 |
28İzleyin | CVE-2020-24063İstismar yok | The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.canto · canto · CWE-918 | Yüksek7,2 | — | %1,5 | 10 Kas 2020 |
26İzleyin | CVE-2020-28978Kavram kanıtı | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.canto · canto · CWE-918 | Orta5,3 | — | %15,4 | 30 Kas 2020 |
26İzleyin | CVE-2020-28977Kavram kanıtı | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.canto · canto · CWE-918 | Orta5,3 | — | %15,4 | 30 Kas 2020 |
- CVE-2023-345241Planlayın
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
KritikCVSS 9,8Kavram kanıtıEPSS %7canto · canto11 Ağu 2023
- CVE-2022-4030539İzleyin
A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network res
KritikCVSS 9,8İstismar yokEPSS %2canto · canto9 Eyl 2022
- CVE-2024-493639İzleyin
Canto <= 3.0.8 - Unauthenticated Remote File Inclusion
KritikCVSS 9,8İstismar yokEPSS %1canto · canto14 Haz 2024
- CVE-2024-2509639İzleyin
WordPress canto plugin <= 3.0.7 - Unauth. Remote Code Execution (RCE) vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %1canto · canto3 Nis 2024
- CVE-2013-741631İzleyin
canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a
YüksekCVSS 7,5İstismar yokEPSS %3canto · canto curses3 Ara 2014
- CVE-2020-2897629İzleyin
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability.
OrtaCVSS 5,3Kavram kanıtıEPSS %28canto · canto30 Kas 2020
- CVE-2020-2406328İzleyin
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.
YüksekCVSS 7,2İstismar yokEPSS %1canto · canto10 Kas 2020
- CVE-2020-2897826İzleyin
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.
OrtaCVSS 5,3Kavram kanıtıEPSS %15canto · canto30 Kas 2020
- CVE-2020-2897726İzleyin
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.
OrtaCVSS 5,3Kavram kanıtıEPSS %15canto · canto30 Kas 2020