İçeriğe atla
Noroxi

kentico kayıtları

kentico üreticisine ait 53 yayımlanmış kayıt.

Tüm kayıtlar

53 kayıt
  • Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    kentico · xperience24 Mar 2025

  • An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95

    kentico · xperience26 Mar 2019

  • Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %73

    kentico · xperience24 Mar 2025

  • CVE-2017-17736
    60Bu hafta

    Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/insta

    KritikCVSS 9,8Kavram kanıtıEPSS %68

    kentico · xperience23 Mar 2018

  • CVE-2025-2749
    59Planlayın

    Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE

    YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %4

    kentico · xperience24 Mar 2025

  • CVE-2025-2748
    42Planlayın

    Kentico Xperience stored cross-site scripting in multiple-file upload functionality

    OrtaCVSS 6,1Kavram kanıtıEPSS %61

    kentico · xperience24 Mar 2025

  • CVE-2021-27581
    40Planlayın

    The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.

    KritikCVSS 9,8İstismar yokEPSS %2

    kentico · kentico cms5 Mar 2021

  • CVE-2025-32370
    39İzleyin

    Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, becaus

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    kentico · xperience6 Nis 2025

  • CVE-2019-12102
    37İzleyin

    Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselect

    KritikCVSS 9,1Kavram kanıtıEPSS %2

    kentico · xperience22 May 2019

  • CVE-2018-19453
    35İzleyin

    Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.

    YüksekCVSS 8,8İstismar yokEPSS %1

    kentico · xperience10 Nis 2019

  • CVE-2025-2794
    34İzleyin

    Kentico Xperience <= 13.0.180 Unsafe Reflection

    YüksekCVSS 8,7İstismar yokEPSS %0

    kentico · xperience31 Mar 2025

  • CVE-2023-53934
    34İzleyin

    Kentico Xperience <= 12.0.98 GetResource Handler Denial of Service

    YüksekCVSS 8,7İstismar yokEPSS %0

    kentico · xperience18 Ara 2025

  • CVE-2020-36890
    34İzleyin

    Kentico Xperience <= 10 Administrator Access Control Bypass

    YüksekCVSS 8,6İstismar yokEPSS %0

    kentico · xperience18 Ara 2025

  • CVE-2019-25229
    34İzleyin

    Kentico Xperience <= 12.0.29 MVC Forms Unrestricted File Upload

    YüksekCVSS 8,7İstismar yokEPSS %0

    kentico · xperience18 Ara 2025

  • CVE-2021-47711
    34İzleyin

    Kentico Xperience <= 13.0.52 Online Marketing Macros SQL Injection

    YüksekCVSS 8,7İstismar yokEPSS %0

    kentico · xperience18 Ara 2025

  • CVE-2018-5282
    31İzleyin

    Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstal

    YüksekCVSS 7,8Kavram kanıtıEPSS %2

    kentico · xperience8 Oca 2018

  • CVE-2018-7046
    30İzleyin

    Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system comma

    YüksekCVSS 7,2İstismar yokEPSS %5

    kentico · xperience20 Şub 2018

  • CVE-2022-32387
    30İzleyin

    In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler.

    YüksekCVSS 7,5İstismar yokEPSS %1

    kentico · xperience18 Tem 2022

  • CVE-2025-5591
    30İzleyin

    Stored Cross-site Scripting (XSS) in Kentico Xperience 13

    YüksekCVSS 7,7İstismar yokEPSS %0

    kentico · xperience4 Oca 2026

  • CVE-2019-6242
    28İzleyin

    Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page.

    YüksekCVSS 7,2İstismar yokEPSS %1

    kentico · xperience8 Şub 2019

  • CVE-2018-6843
    28İzleyin

    Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.

    YüksekCVSS 7,2İstismar yokEPSS %1

    kentico · xperience19 Mar 2018

  • CVE-2022-50686
    27İzleyin

    Kentico Xperience <= 12.0 Portal Engine Form Control Information Disclosure

    OrtaCVSS 6,9İstismar yokEPSS %0

    kentico · xperience18 Ara 2025

  • CVE-2024-58320
    27İzleyin

    Kentico Xperience <= 13.0.159 Authentication Information Disclosure

    OrtaCVSS 6,9İstismar yokEPSS %0

    kentico · xperience18 Ara 2025

  • CVE-2021-47712
    27İzleyin

    Kentico Xperience <= 12.0.102 URL Hashing Cryptography Vulnerability

    OrtaCVSS 6,9İstismar yokEPSS %0

    kentico · xperience18 Ara 2025

  • CVE-2022-50682
    27İzleyin

    Kentico Xperience <= 13.0.79 Routing Engine CRLF Injection

    OrtaCVSS 6,9İstismar yokEPSS %0

    kentico · xperience18 Ara 2025