İçeriğe atla
Noroxi

jeesns kayıtları

jeesns üreticisine ait 21 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
4
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

  1. 18
  2. 21
  3. 22

Çubuk: toplam · koyu kısım: CISA KEV.

Tekrar eden sınıflar

Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.

CWE

Tüm kayıtlar

21 kayıt
  • CVE-2020-19280
    35İzleyin

    Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operat

    YüksekCVSS 8,8İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19295
    25İzleyin

    A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web

    OrtaCVSS 6,1Kavram kanıtıEPSS %4

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19282
    25İzleyin

    A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19283
    25İzleyin

    A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-18035
    24İzleyin

    Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the "CKEditorFuncNu

    OrtaCVSS 6,1İstismar yokEPSS %1

    jeesns · jeesns29 Nis 2021

  • CVE-2020-19287
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scr

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19291
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute arbitrary

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2018-17886
    21İzleyin

    An issue was discovered in JEESNS 1.3.

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns2 Eki 2018

  • CVE-2020-19285
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web sc

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19289
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitra

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19292
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web s

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19293
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web sc

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19286
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary we

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19281
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitra

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2018-19178
    21İzleyin

    In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulne

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns11 Kas 2018

  • CVE-2020-19284
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19288
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web sc

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19294
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary we

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2020-19290
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns9 Eyl 2021

  • CVE-2018-12429
    21İzleyin

    JEESNS through 1.2.1 allows XSS attacks by ordinary users who publish articles containing a crafted payload in order to capture an administr

    OrtaCVSS 5,4İstismar yokEPSS %1

    jeesns · jeesns18 Tem 2018

  • CVE-2022-38550
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web sc

    OrtaCVSS 5,4İstismar yokEPSS %0

    jeesns · jeesns19 Eyl 2022