eramba kayıtları
eramba üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %9,1
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %9,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-20 Improper Input Validation1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2023-36255Silahlaştırılmış | An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path eramba · eramba · CWE-94 | Yüksek8,8 | — | %53,1 | 2 Ağu 2023 |
39İzleyin | CVE-2020-25105İstismar yok | eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).eramba · eramba · CWE-640 | Kritik9,8 | — | %1,1 | 3 Eyl 2020 |
26İzleyin | CVE-2025-55462Kavram kanıtı | A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in teramba · eramba · CWE-942 | Orta6,5 | — | %0,4 | 13 Oca 2026 |
24İzleyin | CVE-2018-7894İstismar yok | Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter)eramba · eramba · CWE-79 | Orta6,1 | — | %0,7 | 9 Mar 2018 |
24İzleyin | CVE-2018-7741İstismar yok | Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.eramba · eramba · CWE-79 | Orta6,1 | — | %0,7 | 7 Mar 2018 |
24İzleyin | CVE-2018-7996İstismar yok | Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.eramba · eramba · CWE-79 | Orta6,1 | — | %0,7 | 9 Mar 2018 |
24İzleyin | CVE-2018-7997İstismar yok | Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV file pollutederamba · eramba · CWE-79 | Orta6,1 | — | %0,6 | 9 Mar 2018 |
21İzleyin | CVE-2020-25104İstismar yok | eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object.eramba · eramba · CWE-79 | Orta5,4 | — | %0,6 | 3 Eyl 2020 |
21İzleyin | CVE-2022-43342İstismar yok | A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary weeramba · eramba · CWE-79 | Orta5,4 | — | %0,5 | 14 Kas 2022 |
21İzleyin | CVE-2024-27593İstismar yok | A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attCWE-79 | Orta5,4 | — | %0,3 | 15 May 2024 |
17İzleyin | CVE-2020-28031İstismar yok | eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.eramba · eramba · CWE-20 | Orta4,3 | — | %0,6 | 2 Kas 2020 |
- CVE-2023-3625551Planlayın
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path
YüksekCVSS 8,8SilahlaştırılmışEPSS %53eramba · eramba2 Ağu 2023
- CVE-2020-2510539İzleyin
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
KritikCVSS 9,8İstismar yokEPSS %1eramba · eramba3 Eyl 2020
- CVE-2025-5546226İzleyin
A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in t
OrtaCVSS 6,5Kavram kanıtıEPSS %0eramba · eramba13 Oca 2026
- CVE-2018-789424İzleyin
Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter)
OrtaCVSS 6,1İstismar yokEPSS %1eramba · eramba9 Mar 2018
- CVE-2018-774124İzleyin
Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.
OrtaCVSS 6,1İstismar yokEPSS %1eramba · eramba7 Mar 2018
- CVE-2018-799624İzleyin
Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.
OrtaCVSS 6,1İstismar yokEPSS %1eramba · eramba9 Mar 2018
- CVE-2018-799724İzleyin
Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV file polluted
OrtaCVSS 6,1İstismar yokEPSS %1eramba · eramba9 Mar 2018
- CVE-2020-2510421İzleyin
eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object.
OrtaCVSS 5,4İstismar yokEPSS %1eramba · eramba3 Eyl 2020
- CVE-2022-4334221İzleyin
A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary we
OrtaCVSS 5,4İstismar yokEPSS %1eramba · eramba14 Kas 2022
- CVE-2024-2759321İzleyin
A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated att
OrtaCVSS 5,4İstismar yokEPSS %015 May 2024
- CVE-2020-2803117İzleyin
eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.
OrtaCVSS 4,3İstismar yokEPSS %1eramba · eramba2 Kas 2020