derbynet kayıtları
derbynet üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-692 Incomplete Denylist to Cross-Site Scripting1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2024-31818İstismar yok | Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.pderbynet · derbynet · CWE-22 | Kritik9,8 | — | %1,9 | 12 Nis 2024 |
39İzleyin | CVE-2024-30922İstismar yok | SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendederbynet · derbynet · CWE-89 | Kritik9,8 | — | %1,4 | 18 Nis 2024 |
39İzleyin | CVE-2024-30923İstismar yok | SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Docuderbynet · derbynet · CWE-94 | Kritik9,8 | — | %1,4 | 18 Nis 2024 |
32İzleyin | CVE-2024-30929İstismar yok | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlisderbynet · derbynet · CWE-79 | Yüksek8,0 | — | %1,0 | 18 Nis 2024 |
32İzleyin | CVE-2024-30928İstismar yok | SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/qderbynet · derbynet · CWE-89 | Yüksek8,1 | — | %0,7 | 18 Nis 2024 |
29İzleyin | CVE-2024-30920İstismar yok | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.phpderbynet · derbynet · CWE-79 | Yüksek7,4 | — | %1,0 | 18 Nis 2024 |
26İzleyin | CVE-2024-30925İstismar yok | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.derbynet · derbynet · CWE-79 | Orta6,5 | — | %0,6 | 18 Nis 2024 |
25İzleyin | CVE-2024-30927İstismar yok | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php componentderbynet · derbynet · CWE-79 | Orta6,3 | — | %0,6 | 18 Nis 2024 |
21İzleyin | CVE-2024-30921İstismar yok | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php componentderbynet · derbynet · CWE-79 | Orta5,4 | — | %0,6 | 18 Nis 2024 |
18İzleyin | CVE-2024-30926İstismar yok | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component.derbynet · derbynet · CWE-79 | Orta4,6 | — | %0,5 | 18 Nis 2024 |
18İzleyin | CVE-2024-30924İstismar yok | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.derbynet · derbynet · CWE-692 | Orta4,6 | — | %0,3 | 18 Nis 2024 |
- CVE-2024-3181840Planlayın
Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.p
KritikCVSS 9,8İstismar yokEPSS %2derbynet · derbynet12 Nis 2024
- CVE-2024-3092239İzleyin
SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rende
KritikCVSS 9,8İstismar yokEPSS %1derbynet · derbynet18 Nis 2024
- CVE-2024-3092339İzleyin
SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Docu
KritikCVSS 9,8İstismar yokEPSS %1derbynet · derbynet18 Nis 2024
- CVE-2024-3092932İzleyin
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlis
YüksekCVSS 8,0İstismar yokEPSS %1derbynet · derbynet18 Nis 2024
- CVE-2024-3092832İzleyin
SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/q
YüksekCVSS 8,1İstismar yokEPSS %1derbynet · derbynet18 Nis 2024
- CVE-2024-3092029İzleyin
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php
YüksekCVSS 7,4İstismar yokEPSS %1derbynet · derbynet18 Nis 2024
- CVE-2024-3092526İzleyin
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.
OrtaCVSS 6,5İstismar yokEPSS %1derbynet · derbynet18 Nis 2024
- CVE-2024-3092725İzleyin
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component
OrtaCVSS 6,3İstismar yokEPSS %1derbynet · derbynet18 Nis 2024
- CVE-2024-3092121İzleyin
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component
OrtaCVSS 5,4İstismar yokEPSS %1derbynet · derbynet18 Nis 2024
- CVE-2024-3092618İzleyin
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component.
OrtaCVSS 4,6İstismar yokEPSS %1derbynet · derbynet18 Nis 2024
- CVE-2024-3092418İzleyin
Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.
OrtaCVSS 4,6İstismar yokEPSS %0derbynet · derbynet18 Nis 2024