İçeriğe atla
Noroxi

Enhancesoft kayıtları

enhancesoft üreticisine ait 47 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %2,1
Pre-auth RCE
4
Düzeltme kaydı olan
%2,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

47 kayıt
  • CVE-2020-24881
    61Bu hafta

    SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

    KritikCVSS 9,8Kavram kanıtıEPSS %73

    enhancesoft · osticket2 Kas 2020

  • CVE-2026-22200
    56Planlayın

    osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read

    YüksekCVSS 8,7SilahlaştırılmışEPSS %74

    enhancesoft · osticket12 Oca 2026

  • CVE-2022-31890
    39İzleyin

    SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    enhancesoft · audit log5 Nis 2023

  • CVE-2021-42235
    39İzleyin

    SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration p

    KritikCVSS 9,8İstismar yokEPSS %1

    enhancesoft · osticket4 May 2022

  • CVE-2019-14749
    38İzleyin

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1.

    YüksekCVSS 8,8Kavram kanıtıEPSS %10

    enhancesoft · osticket7 Ağu 2019

  • CVE-2022-31888
    35İzleyin

    Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

    YüksekCVSS 8,8İstismar yokEPSS %1

    enhancesoft · osticket5 Nis 2023

  • CVE-2009-2361
    32İzleyin

    SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands

    YüksekCVSS 7,5Kavram kanıtıEPSS %5

    enhancesoft · osticket8 Tem 2009

  • CVE-2018-7195
    32İzleyin

    Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leve

    YüksekCVSS 8,1İstismar yokEPSS %1

    enhancesoft · osticket27 Mar 2018

  • CVE-2010-0605
    31İzleyin

    SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    osticket · osticket11 Şub 2010

  • CVE-2005-1439
    31İzleyin

    Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via ..

    YüksekCVSS 7,5İstismar yokEPSS %2

    enhancesoft · osticket3 May 2005

  • CVE-2006-5407
    30İzleyin

    PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the

    YüksekCVSS 7,5İstismar yokEPSS %1

    enhancesoft · osticket18 Eki 2006

  • CVE-2023-30082
    30İzleyin

    A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied

    YüksekCVSS 7,5İstismar yokEPSS %1

    enhancesoft · osticket14 Haz 2023

  • CVE-2005-1436
    28İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t

    OrtaCVSS 6,8İstismar yokEPSS %2

    enhancesoft · osticket3 May 2005

  • CVE-2019-14750
    27İzleyin

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1.

    OrtaCVSS 6,1Kavram kanıtıEPSS %11

    enhancesoft · osticket7 Ağu 2019

  • CVE-2021-45811
    27İzleyin

    A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execu

    OrtaCVSS 6,5Kavram kanıtıEPSS %2

    enhancesoft · osticket7 Eyl 2023

  • CVE-2025-26241
    26İzleyin

    A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to exe

    OrtaCVSS 6,5İstismar yokEPSS %0

    enhancesoft · osticket5 May 2025

  • CVE-2019-11537
    25İzleyin

    In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an

    OrtaCVSS 6,1Kavram kanıtıEPSS %5

    enhancesoft · osticket25 Nis 2019

  • CVE-2018-7196
    25İzleyin

    Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    enhancesoft · osticket27 Mar 2018

  • CVE-2018-7193
    25İzleyin

    Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbit

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    enhancesoft · osticket27 Mar 2018

  • CVE-2018-7192
    25İzleyin

    Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to injec

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    enhancesoft · osticket27 Mar 2018

  • CVE-2020-24917
    24İzleyin

    osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    enhancesoft · osticket30 Ağu 2020

  • CVE-2019-13397
    24İzleyin

    Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML vi

    OrtaCVSS 6,1İstismar yokEPSS %1

    enhancesoft · osticket9 Tem 2019

  • CVE-2020-22609
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    enhancesoft · osticket28 Haz 2021

  • CVE-2020-22608
    24İzleyin

    Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    enhancesoft · osticket28 Haz 2021

  • CVE-2022-31889
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    enhancesoft · audit log5 Nis 2023