Intermesh kayıtları
intermesh üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-502 Deserialization of Untrusted Data1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-34838Kavram kanıtı | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`intermesh · group-office · CWE-502 | Kritik9,9 | — | %1,0 | 2 Nis 2026 |
37İzleyin | CVE-2026-27947İstismar yok | Group-Office Vulnerable to Remote Code Execution (RCE)intermesh · group-office · CWE-88 | Kritik9,4 | — | %1,0 | 27 Şub 2026 |
35İzleyin | CVE-2026-33755İstismar yok | Authenticated SQL Injection in Contact/query addressBookIds filterintermesh · group-office · CWE-89 | Yüksek8,8 | — | %0,5 | 27 Mar 2026 |
30İzleyin | CVE-2010-3428Kavram kanıtı | SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commaintermesh · group-office · CWE-89 | Yüksek7,5 | — | %1,0 | 16 Eyl 2010 |
28İzleyin | CVE-2026-27832İstismar yok | Group-Office Has Authenticated SQL Injection in advancedQueryData.comparatorintermesh · group-office · CWE-89 | Yüksek7,1 | — | %0,5 | 27 Şub 2026 |
27İzleyin | CVE-2025-48366İstismar yok | GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actionsintermesh · group-office · CWE-79 | Orta6,9 | — | %0,3 | 22 May 2025 |
23İzleyin | CVE-2025-48368İstismar yok | GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Executionintermesh · group-office · CWE-79 | Orta5,8 | — | %0,3 | 22 May 2025 |
21İzleyin | CVE-2025-48369İstismar yok | GroupOffice vulnerable to Stored XSS in Tasks Comment Sectionintermesh · group-office · CWE-79 | Orta5,3 | — | %0,3 | 22 May 2025 |
21İzleyin | CVE-2025-48993İstismar yok | Group-Office vulnerable to reflected XSS via Look and Feel Formatting inputintermesh · group-office · CWE-79 | Orta5,3 | — | %0,3 | 16 Haz 2025 |
20İzleyin | CVE-2026-30238İstismar yok | Group-Office: Reflected XSS in JavaScript contextintermesh · group-office · CWE-79 | Orta5,1 | — | %0,3 | 6 Mar 2026 |
20İzleyin | CVE-2025-48992İstismar yok | Group-Office vulnerable to blind XSSintermesh · group-office · CWE-79 | Orta5,2 | — | %0,3 | 16 Haz 2025 |
8İzleyin | CVE-2026-30237İstismar yok | Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php)intermesh · group-office · CWE-79 | Düşük2,1 | — | %0,3 | 6 Mar 2026 |
- CVE-2026-3483839İzleyin
Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`
KritikCVSS 9,9Kavram kanıtıEPSS %1intermesh · group-office2 Nis 2026
- CVE-2026-2794737İzleyin
Group-Office Vulnerable to Remote Code Execution (RCE)
KritikCVSS 9,4İstismar yokEPSS %1intermesh · group-office27 Şub 2026
- CVE-2026-3375535İzleyin
Authenticated SQL Injection in Contact/query addressBookIds filter
YüksekCVSS 8,8İstismar yokEPSS %0intermesh · group-office27 Mar 2026
- CVE-2010-342830İzleyin
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL comma
YüksekCVSS 7,5Kavram kanıtıEPSS %1intermesh · group-office16 Eyl 2010
- CVE-2026-2783228İzleyin
Group-Office Has Authenticated SQL Injection in advancedQueryData.comparator
YüksekCVSS 7,1İstismar yokEPSS %0intermesh · group-office27 Şub 2026
- CVE-2025-4836627İzleyin
GroupOffice's Blind Stored XSS in Phone Number Field Enables Forced Redirect and Unauthorized Actions
OrtaCVSS 6,9İstismar yokEPSS %0intermesh · group-office22 May 2025
- CVE-2025-4836823İzleyin
GroupOffice's DOM-Based XSS in all Date Input Fields Allows Arbitrary JavaScript Execution
OrtaCVSS 5,8İstismar yokEPSS %0intermesh · group-office22 May 2025
- CVE-2025-4836921İzleyin
GroupOffice vulnerable to Stored XSS in Tasks Comment Section
OrtaCVSS 5,3İstismar yokEPSS %0intermesh · group-office22 May 2025
- CVE-2025-4899321İzleyin
Group-Office vulnerable to reflected XSS via Look and Feel Formatting input
OrtaCVSS 5,3İstismar yokEPSS %0intermesh · group-office16 Haz 2025
- CVE-2026-3023820İzleyin
Group-Office: Reflected XSS in JavaScript context
OrtaCVSS 5,1İstismar yokEPSS %0intermesh · group-office6 Mar 2026
- CVE-2025-4899220İzleyin
Group-Office vulnerable to blind XSS
OrtaCVSS 5,2İstismar yokEPSS %0intermesh · group-office16 Haz 2025
- CVE-2026-302378İzleyin
Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php)
DüşükCVSS 2,1İstismar yokEPSS %0intermesh · group-office6 Mar 2026