İçeriğe atla
Noroxi

dnnsoftware kayıtları

dnnsoftware üreticisine ait 76 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
3 · %3,9
Silahlaştırılmış
5 · %6,6
Pre-auth RCE
1
Düzeltme kaydı olan
%59,2
Yayından KEV’e ortanca
854 gün

Tüm kayıtlar

76 kayıt
  • DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN site

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %95

    dnnsoftware · dotnetnuke20 Tem 2017

  • DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %76

    dnnsoftware · dotnetnuke3 Tem 2019

  • DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters.

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %74

    dnnsoftware · dotnetnuke3 Tem 2019

  • CVE-2015-2794
    62Bu hafta

    The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via

    KritikCVSS 9,8Kavram kanıtıEPSS %75

    dnnsoftware · dotnetnuke6 Şub 2017

  • CVE-2025-64095
    53Planlayın

    DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

    KritikCVSS 9,8Kavram kanıtıEPSS %47

    dnnsoftware · dotnetnuke28 Eki 2025

  • CVE-2018-18326
    46Planlayın

    DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.

    YüksekCVSS 7,5SilahlaştırılmışEPSS %54

    dnnsoftware · dotnetnuke3 Tem 2019

  • CVE-2025-52488
    45Planlayın

    DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input

    YüksekCVSS 8,6Kavram kanıtıEPSS %36

    dnnsoftware · dotnetnuke20 Haz 2025

  • CVE-2018-15812
    44Planlayın

    DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.

    YüksekCVSS 7,5SilahlaştırılmışEPSS %47

    dnnsoftware · dotnetnuke3 Tem 2019

  • CVE-2006-3601
    41Planlayın

    ** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gai

    KritikCVSS 10,0İstismar yokEPSS %2

    dnnsoftware · dotnetnuke18 Tem 2006

  • CVE-2020-5187
    36İzleyin

    DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).

    YüksekCVSS 8,8İstismar yokEPSS %2

    dnnsoftware · dotnetnuke24 Şub 2020

  • CVE-2025-59545
    36İzleyin

    DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module

    KritikCVSS 9,0İstismar yokEPSS %0

    dnnsoftware · dotnetnuke23 Eyl 2025

  • CVE-2025-52487
    35İzleyin

    DNN.PLATFORM possibly allows bypass of IP Filters

    YüksekCVSS 8,8İstismar yokEPSS %0

    dnnsoftware · dotnetnuke20 Haz 2025

  • CVE-2017-0929
    34İzleyin

    DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class.

    YüksekCVSS 7,5Kavram kanıtıEPSS %13

    dnnsoftware · dotnetnuke3 Tem 2018

  • CVE-2026-40321
    32İzleyin

    DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload

    YüksekCVSS 8,0İstismar yokEPSS %0

    dnnsoftware · dotnetnuke17 Nis 2026

  • CVE-2008-7102
    30İzleyin

    DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality

    YüksekCVSS 7,5İstismar yokEPSS %1

    dnnsoftware · dotnetnuke27 Ağu 2009

  • CVE-2004-2324
    30İzleyin

    SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend da

    YüksekCVSS 7,5İstismar yokEPSS %1

    dnnsoftware · dotnetnuke31 Ara 2004

  • CVE-2021-40186
    30İzleyin

    DNN CMS Server-Side Request Forgery (SSRF)

    YüksekCVSS 7,5İstismar yokEPSS %1

    dnnsoftware · dotnetnuke2 Haz 2022

  • CVE-2025-32374
    30İzleyin

    Possible Denial of Service (DoS) in DNN.PLATFORM registration

    YüksekCVSS 7,5İstismar yokEPSS %0

    dnnsoftware · dotnetnuke9 Nis 2025

  • CVE-2025-32372
    30İzleyin

    Server-Side Request Forgery (SSRF) in DotNetNuke.Core

    YüksekCVSS 7,5İstismar yokEPSS %0

    dnnsoftware · dotnetnuke9 Nis 2025

  • CVE-2025-32035
    30İzleyin

    DNN does not check the contents of a file when uploading files

    YüksekCVSS 7,5İstismar yokEPSS %0

    dnnsoftware · dotnetnuke8 Nis 2025

  • CVE-2020-5188
    27İzleyin

    DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.

    OrtaCVSS 6,5İstismar yokEPSS %2

    dnnsoftware · dotnetnuke24 Şub 2020

  • CVE-2008-6541
    27İzleyin

    Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrar

    OrtaCVSS 6,8İstismar yokEPSS %1

    dnnsoftware · dotnetnuke29 Mar 2009

  • CVE-2026-40306
    27İzleyin

    DNN has same HostGUID for all new installs

    OrtaCVSS 6,9İstismar yokEPSS %0

    dnnsoftware · dotnetnuke17 Nis 2026

  • CVE-2019-12562
    26İzleyin

    Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into th

    OrtaCVSS 6,1Kavram kanıtıEPSS %6

    dnnsoftware · dotnetnuke26 Eyl 2019

  • CVE-2008-6399
    26İzleyin

    Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknow

    OrtaCVSS 6,4İstismar yokEPSS %2

    dnnsoftware · dotnetnuke5 Mar 2009