ironmansoftware kayıtları
ironmansoftware üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-1289 Improper Validation of Unsafe Equivalence in Input1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-269 Improper Privilege Management1
- CWE-306 Missing Authentication for Critical Function1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2023-49213İstismar yok | The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP ironmansoftware · powershell universal · CWE-77 | Yüksek8,8 | — | %2,1 | 23 Kas 2023 |
35İzleyin | CVE-2022-45183İstismar yok | Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token toironmansoftware · powershell universal · CWE-269 | Yüksek8,8 | — | %0,8 | 14 Kas 2022 |
35İzleyin | CVE-2024-50616İstismar yok | Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information. | Yüksek8,8 | — | %0,4 | 27 Eki 2024 |
33İzleyin | CVE-2026-4064İstismar yok | Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with anironmansoftware · powershell universal · CWE-862 | Yüksek8,3 | — | %0,4 | 17 Mar 2026 |
29İzleyin | CVE-2022-45184İstismar yok | The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory,ironmansoftware · powershell universal · CWE-22 | Yüksek7,2 | — | %2,0 | 14 Kas 2022 |
26İzleyin | CVE-2026-3277İstismar yok | The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext iironmansoftware · powershell universal · CWE-312 | Orta6,5 | — | %0,2 | 27 Şub 2026 |
24İzleyin | CVE-2026-0618İstismar yok | Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13.ironmansoftware · powershell universal · CWE-79 | Orta6,1 | — | %0,2 | 7 Oca 2026 |
22İzleyin | CVE-2026-3563İstismar yok | Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with ironmansoftware · powershell universal · CWE-1289 | Orta5,5 | — | %0,4 | 17 Mar 2026 |
21İzleyin | CVE-2026-8694İstismar yok | Improper access control on the API documentation endpoint in PowerShell Universalironmansoftware · powershell universal · CWE-306 | Orta5,3 | — | %0,4 | 12 Haz 2026 |
- CVE-2023-4921336İzleyin
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP
YüksekCVSS 8,8İstismar yokEPSS %2ironmansoftware · powershell universal23 Kas 2023
- CVE-2022-4518335İzleyin
Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to
YüksekCVSS 8,8İstismar yokEPSS %1ironmansoftware · powershell universal14 Kas 2022
- CVE-2024-5061635İzleyin
Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information.
YüksekCVSS 8,8İstismar yokEPSS %027 Eki 2024
- CVE-2026-406433İzleyin
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with an
YüksekCVSS 8,3İstismar yokEPSS %0ironmansoftware · powershell universal17 Mar 2026
- CVE-2022-4518429İzleyin
The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory,
YüksekCVSS 7,2İstismar yokEPSS %2ironmansoftware · powershell universal14 Kas 2022
- CVE-2026-327726İzleyin
The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext i
OrtaCVSS 6,5İstismar yokEPSS %0ironmansoftware · powershell universal27 Şub 2026
- CVE-2026-061824İzleyin
Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13.
OrtaCVSS 6,1İstismar yokEPSS %0ironmansoftware · powershell universal7 Oca 2026
- CVE-2026-356322İzleyin
Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with
OrtaCVSS 5,5İstismar yokEPSS %0ironmansoftware · powershell universal17 Mar 2026
- CVE-2026-869421İzleyin
Improper access control on the API documentation endpoint in PowerShell Universal
OrtaCVSS 5,3İstismar yokEPSS %0ironmansoftware · powershell universal12 Haz 2026