geeeeeeeek kayıtları
geeeeeeeek üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-28100İstismar yok | A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at tgeeeeeeeek · dingfanzu · CWE-89 | Kritik9,8 | — | %0,6 | 15 Nis 2025 |
26İzleyin | CVE-2024-50651İstismar yok | java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs geeeeeeeek · java shop · CWE-639 | Orta6,5 | — | %0,5 | 15 Kas 2024 |
21İzleyin | CVE-2024-8302İstismar yok | dingfanzu CMS chpwd.php sql injectiongeeeeeeeek · dingfanzu · CWE-89 | Orta5,3 | — | %0,8 | 29 Ağu 2024 |
17İzleyin | CVE-2024-50652İstismar yok | A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.geeeeeeeek · java shop · CWE-434 | Orta4,3 | — | %0,3 | 15 Kas 2024 |
14İzleyin | CVE-2024-48341İstismar yok | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShopgeeeeeeeek · dingfanzu · CWE-352 | Düşük3,7 | — | %0,2 | 8 Eyl 2025 |
- CVE-2025-2810039İzleyin
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at t
KritikCVSS 9,8İstismar yokEPSS %1geeeeeeeek · dingfanzu15 Nis 2025
- CVE-2024-5065126İzleyin
java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs
OrtaCVSS 6,5İstismar yokEPSS %0geeeeeeeek · java shop15 Kas 2024
- CVE-2024-830221İzleyin
dingfanzu CMS chpwd.php sql injection
OrtaCVSS 5,3İstismar yokEPSS %1geeeeeeeek · dingfanzu29 Ağu 2024
- CVE-2024-5065217İzleyin
A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.
OrtaCVSS 4,3İstismar yokEPSS %0geeeeeeeek · java shop15 Kas 2024
- CVE-2024-4834114İzleyin
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop
DüşükCVSS 3,7İstismar yokEPSS %0geeeeeeeek · dingfanzu8 Eyl 2025