icz kayıtları
icz üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2026-24913İstismar yok | SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier.icz · matcha invoice · CWE-89 | Yüksek8,7 | — | %0,3 | 8 Nis 2026 |
27İzleyin | CVE-2015-5643İstismar yok | The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitraricz · matchasns · CWE-94 | Orta6,8 | — | %1,3 | 5 Eki 2015 |
27İzleyin | CVE-2015-5644İstismar yok | The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHicz · matchasns · CWE-94 | Orta6,8 | — | %1,3 | 5 Eki 2015 |
27İzleyin | CVE-2012-1237İstismar yok | Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitraryicz · sencha sns · CWE-352 | Orta6,8 | — | %0,6 | 6 Nis 2012 |
26İzleyin | CVE-2015-5645İstismar yok | ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.icz · matchasns · CWE-264 | Orta6,5 | — | %1,3 | 5 Eki 2015 |
26İzleyin | CVE-2015-5642İstismar yok | Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commandsicz · matchasns · CWE-89 | Orta6,5 | — | %1,0 | 5 Eki 2015 |
20İzleyin | CVE-2026-33273İstismar yok | Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier.icz · matcha invoice · CWE-434 | Orta5,1 | — | %0,4 | 8 Nis 2026 |
20İzleyin | CVE-2026-27787İstismar yok | Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier.icz · matcha sns · CWE-79 | Orta5,1 | — | %0,2 | 8 Nis 2026 |
17İzleyin | CVE-2012-1238İstismar yok | Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.icz · sencha sns | Orta4,3 | — | %1,2 | 6 Nis 2012 |
- CVE-2026-2491334İzleyin
SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier.
YüksekCVSS 8,7İstismar yokEPSS %0icz · matcha invoice8 Nis 2026
- CVE-2015-564327İzleyin
The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrar
OrtaCVSS 6,8İstismar yokEPSS %1icz · matchasns5 Eki 2015
- CVE-2015-564427İzleyin
The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PH
OrtaCVSS 6,8İstismar yokEPSS %1icz · matchasns5 Eki 2015
- CVE-2012-123727İzleyin
Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitrary
OrtaCVSS 6,8İstismar yokEPSS %1icz · sencha sns6 Nis 2012
- CVE-2015-564526İzleyin
ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.
OrtaCVSS 6,5İstismar yokEPSS %1icz · matchasns5 Eki 2015
- CVE-2015-564226İzleyin
Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commands
OrtaCVSS 6,5İstismar yokEPSS %1icz · matchasns5 Eki 2015
- CVE-2026-3327320İzleyin
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier.
OrtaCVSS 5,1İstismar yokEPSS %0icz · matcha invoice8 Nis 2026
- CVE-2026-2778720İzleyin
Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier.
OrtaCVSS 5,1İstismar yokEPSS %0icz · matcha sns8 Nis 2026
- CVE-2012-123817İzleyin
Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.
OrtaCVSS 4,3İstismar yokEPSS %1icz · sencha sns6 Nis 2012