İçeriğe atla
Noroxi

froxlor kayıtları

froxlor üreticisine ait 48 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %2,1
Pre-auth RCE
1
Düzeltme kaydı olan
%91,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

48 kayıt
  • CVE-2023-0315
    64Bu hafta

    Command Injection in froxlor/froxlor

    YüksekCVSS 8,8SilahlaştırılmışEPSS %98

    froxlor · froxlor15 Oca 2023

  • CVE-2023-2034
    56Planlayın

    Unrestricted Upload of File with Dangerous Type in froxlor/froxlor

    YüksekCVSS 8,8İstismar yokEPSS %71

    froxlor · froxlor13 Nis 2023

  • CVE-2021-42325
    43Planlayın

    Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.

    KritikCVSS 9,8Kavram kanıtıEPSS %12

    froxlor · froxlor12 Eki 2021

  • CVE-2015-5959
    40Planlayın

    Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/s

    KritikCVSS 9,8İstismar yokEPSS %3

    froxlor · froxlor6 Eyl 2017

  • CVE-2016-5100
    40Planlayın

    Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the passw

    KritikCVSS 9,8İstismar yokEPSS %2

    froxlor · froxlor13 Şub 2017

  • CVE-2023-3173
    39İzleyin

    Improper Restriction of Excessive Authentication Attempts in froxlor/froxlor

    KritikCVSS 9,8İstismar yokEPSS %1

    froxlor · froxlor8 Haz 2023

  • CVE-2023-1307
    39İzleyin

    Authentication Bypass by Primary Weakness in froxlor/froxlor

    KritikCVSS 9,8İstismar yokEPSS %1

    froxlor · froxlor9 Mar 2023

  • CVE-2026-41228
    39İzleyin

    Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution

    KritikCVSS 9,9İstismar yokEPSS %1

    froxlor · froxlor23 Nis 2026

  • CVE-2024-34070
    38İzleyin

    Froxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise

    KritikCVSS 9,6Kavram kanıtıEPSS %1

    froxlor · froxlor14 May 2024

  • CVE-2023-0877
    36İzleyin

    Code Injection in froxlor/froxlor

    YüksekCVSS 8,8İstismar yokEPSS %4

    froxlor · froxlor16 Şub 2023

  • CVE-2020-10235
    36İzleyin

    An issue was discovered in Froxlor before 0.10.14.

    YüksekCVSS 8,8İstismar yokEPSS %2

    froxlor · froxlor9 Mar 2020

  • CVE-2026-26279
    36İzleyin

    Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection

    KritikCVSS 9,1İstismar yokEPSS %1

    froxlor · froxlor3 Mar 2026

  • CVE-2026-41229
    36İzleyin

    Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)

    KritikCVSS 9,1İstismar yokEPSS %1

    froxlor · froxlor23 Nis 2026

  • CVE-2023-0671
    35İzleyin

    Code Injection in froxlor/froxlor

    YüksekCVSS 8,8İstismar yokEPSS %1

    froxlor · froxlor3 Şub 2023

  • CVE-2023-6069
    35İzleyin

    Improper Link Resolution Before File Access in froxlor/froxlor

    YüksekCVSS 8,8İstismar yokEPSS %1

    froxlor · froxlor9 Kas 2023

  • CVE-2023-1033
    35İzleyin

    Cross-Site Request Forgery (CSRF) in froxlor/froxlor

    YüksekCVSS 8,8İstismar yokEPSS %0

    froxlor · froxlor24 Şub 2023

  • CVE-2026-30932
    34İzleyin

    Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API

    YüksekCVSS 8,6İstismar yokEPSS %1

    froxlor · froxlor24 Mar 2026

  • CVE-2026-41230
    34İzleyin

    Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()

    YüksekCVSS 8,5İstismar yokEPSS %1

    froxlor · froxlor23 Nis 2026

  • CVE-2025-29773
    31İzleyin

    Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover

    YüksekCVSS 7,8İstismar yokEPSS %0

    froxlor · froxlor13 Mar 2025

  • CVE-2018-12642
    30İzleyin

    Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.

    YüksekCVSS 7,5İstismar yokEPSS %1

    froxlor · froxlor22 Haz 2018

  • CVE-2023-50256
    30İzleyin

    Froxlor username/surname AND company field Bypass

    YüksekCVSS 7,5İstismar yokEPSS %1

    froxlor · froxlor3 Oca 2024

  • CVE-2023-2666
    30İzleyin

    Allocation of Resources Without Limits or Throttling in froxlor/froxlor

    YüksekCVSS 7,5İstismar yokEPSS %1

    froxlor · froxlor11 May 2023

  • CVE-2026-41231
    30İzleyin

    Froxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cron

    YüksekCVSS 7,5İstismar yokEPSS %1

    froxlor · froxlor23 Nis 2026

  • CVE-2023-0564
    30İzleyin

    Weak Password Requirements in froxlor/froxlor

    YüksekCVSS 7,5İstismar yokEPSS %0

    froxlor · froxlor28 Oca 2023

  • Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclo

    YüksekCVSS 7,2İstismar yokEPSS %3

    froxlor · froxlor26 Haz 2018