filecloud kayıtları
filecloud üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %14,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-284 Improper Access Control1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2022-25241Kavram kanıtı | In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).filecloud · filecloud · CWE-352 | Yüksek8,8 | — | %3,3 | 15 Şub 2022 |
35İzleyin | CVE-2016-6578İstismar yok | CodeLathe FileCloud, version 13.0.0.32841 and earlier, is vulnerable to cross-site request forgery (CSRF)filecloud · filecloud · CWE-352 | Yüksek8,8 | — | %0,9 | 13 Tem 2018 |
35İzleyin | CVE-2022-25242İstismar yok | In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).filecloud · filecloud · CWE-352 | Yüksek8,8 | — | %0,4 | 15 Şub 2022 |
29İzleyin | CVE-2022-39833İstismar yok | FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported APIfilecloud · filecloud · CWE-94 | Yüksek7,2 | — | %2,8 | 23 Kas 2022 |
26İzleyin | CVE-2022-1958İstismar yok | FileCloud NTFS access controlfilecloud · filecloud · CWE-284 | Orta6,5 | — | %0,7 | 15 Haz 2022 |
21İzleyin | CVE-2020-26524İstismar yok | CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.filecloud · filecloud | Orta5,3 | — | %1,4 | 2 Eki 2020 |
21İzleyin | CVE-2022-24633İstismar yok | All versions of FileCloud prior to 21.3 are vulnerable to user enumeration.filecloud · filecloud · CWE-200 | Orta5,3 | — | %0,8 | 24 Şub 2022 |
- CVE-2022-2524136İzleyin
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
YüksekCVSS 8,8Kavram kanıtıEPSS %3filecloud · filecloud15 Şub 2022
- CVE-2016-657835İzleyin
CodeLathe FileCloud, version 13.0.0.32841 and earlier, is vulnerable to cross-site request forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %1filecloud · filecloud13 Tem 2018
- CVE-2022-2524235İzleyin
In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).
YüksekCVSS 8,8İstismar yokEPSS %0filecloud · filecloud15 Şub 2022
- CVE-2022-3983329İzleyin
FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API
YüksekCVSS 7,2İstismar yokEPSS %3filecloud · filecloud23 Kas 2022
- CVE-2022-195826İzleyin
FileCloud NTFS access control
OrtaCVSS 6,5İstismar yokEPSS %1filecloud · filecloud15 Haz 2022
- CVE-2020-2652421İzleyin
CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
OrtaCVSS 5,3İstismar yokEPSS %1filecloud · filecloud2 Eki 2020
- CVE-2022-2463321İzleyin
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration.
OrtaCVSS 5,3İstismar yokEPSS %1filecloud · filecloud24 Şub 2022