İçeriğe atla
Noroxi

eramba kayıtları

eramba üreticisine ait 11 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %9,1
Pre-auth RCE
0
Düzeltme kaydı olan
%9,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

11 kayıt
  • CVE-2023-36255
    51Planlayın

    An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path

    YüksekCVSS 8,8SilahlaştırılmışEPSS %53

    eramba · eramba2 Ağu 2023

  • CVE-2020-25105
    39İzleyin

    eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).

    KritikCVSS 9,8İstismar yokEPSS %1

    eramba · eramba3 Eyl 2020

  • CVE-2025-55462
    26İzleyin

    A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in t

    OrtaCVSS 6,5Kavram kanıtıEPSS %0

    eramba · eramba13 Oca 2026

  • CVE-2018-7894
    24İzleyin

    Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter)

    OrtaCVSS 6,1İstismar yokEPSS %1

    eramba · eramba9 Mar 2018

  • CVE-2018-7741
    24İzleyin

    Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.

    OrtaCVSS 6,1İstismar yokEPSS %1

    eramba · eramba7 Mar 2018

  • CVE-2018-7996
    24İzleyin

    Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.

    OrtaCVSS 6,1İstismar yokEPSS %1

    eramba · eramba9 Mar 2018

  • CVE-2018-7997
    24İzleyin

    Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV file polluted

    OrtaCVSS 6,1İstismar yokEPSS %1

    eramba · eramba9 Mar 2018

  • CVE-2020-25104
    21İzleyin

    eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object.

    OrtaCVSS 5,4İstismar yokEPSS %1

    eramba · eramba3 Eyl 2020

  • CVE-2022-43342
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary we

    OrtaCVSS 5,4İstismar yokEPSS %1

    eramba · eramba14 Kas 2022

  • CVE-2024-27593
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated att

    OrtaCVSS 5,4İstismar yokEPSS %0

    15 May 2024

  • CVE-2020-28031
    17İzleyin

    eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.

    OrtaCVSS 4,3İstismar yokEPSS %1

    eramba · eramba2 Kas 2020