GestSup kayıtları
gestsup üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2021-31646İstismar yok | Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote).gestsup · gestsup · CWE-307 | Kritik9,8 | — | %1,3 | 26 Nis 2021 |
35İzleyin | CVE-2026-22194İstismar yok | GestSup <= 3.2.60 CSRF Allows Privileged Actionsgestsup · gestsup · CWE-352 | Yüksek8,9 | — | %0,2 | 9 Oca 2026 |
30İzleyin | CVE-2026-22197İstismar yok | GestSup < 3.2.60 Multiple SQL Injections in Asset Listgestsup · gestsup · CWE-89 | Yüksek7,5 | — | %0,3 | 9 Oca 2026 |
30İzleyin | CVE-2026-22195İstismar yok | GestSup < 3.2.60 SQL Injection in Search Bargestsup · gestsup · CWE-89 | Yüksek7,7 | — | %0,3 | 9 Oca 2026 |
30İzleyin | CVE-2026-22196İstismar yok | GestSup < 3.2.60 SQL Injection in Ticket Creationgestsup · gestsup · CWE-89 | Yüksek7,7 | — | %0,3 | 9 Oca 2026 |
21İzleyin | CVE-2023-52059İstismar yok | A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payloagestsup · gestsup · CWE-79 | Orta5,4 | — | %0,4 | 12 Şub 2024 |
20İzleyin | CVE-2026-22198İstismar yok | GestSup < 3.2.60 Stored XSS in API Error Logsgestsup · gestsup · CWE-79 | Orta5,1 | — | %0,3 | 9 Oca 2026 |
17İzleyin | CVE-2023-52060İstismar yok | A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.gestsup · gestsup · CWE-352 | Orta4,3 | — | %0,3 | 12 Şub 2024 |
- CVE-2021-3164639İzleyin
Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote).
KritikCVSS 9,8İstismar yokEPSS %1gestsup · gestsup26 Nis 2021
- CVE-2026-2219435İzleyin
GestSup <= 3.2.60 CSRF Allows Privileged Actions
YüksekCVSS 8,9İstismar yokEPSS %0gestsup · gestsup9 Oca 2026
- CVE-2026-2219730İzleyin
GestSup < 3.2.60 Multiple SQL Injections in Asset List
YüksekCVSS 7,5İstismar yokEPSS %0gestsup · gestsup9 Oca 2026
- CVE-2026-2219530İzleyin
GestSup < 3.2.60 SQL Injection in Search Bar
YüksekCVSS 7,7İstismar yokEPSS %0gestsup · gestsup9 Oca 2026
- CVE-2026-2219630İzleyin
GestSup < 3.2.60 SQL Injection in Ticket Creation
YüksekCVSS 7,7İstismar yokEPSS %0gestsup · gestsup9 Oca 2026
- CVE-2023-5205921İzleyin
A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payloa
OrtaCVSS 5,4İstismar yokEPSS %0gestsup · gestsup12 Şub 2024
- CVE-2026-2219820İzleyin
GestSup < 3.2.60 Stored XSS in API Error Logs
OrtaCVSS 5,1İstismar yokEPSS %0gestsup · gestsup9 Oca 2026
- CVE-2023-5206017İzleyin
A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.
OrtaCVSS 4,3İstismar yokEPSS %0gestsup · gestsup12 Şub 2024