kentico kayıtları
kentico üreticisine ait 53 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 4 · %7,5
- Silahlaştırılmış
- 4 · %7,5
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 301 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')24
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-288 Authentication Bypass Using an Alternate Path or Channel2
- CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
53 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2025-2747Silahlaştırılmış | Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypasskentico · xperience · CWE-288 | Kritik9,8 | KEV | %97,2 | 24 Mar 2025 |
98Hemen | CVE-2019-10068Silahlaştırılmış | An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions.kentico · xperience · CWE-502 | Kritik9,8 | KEV | %95,1 | 26 Mar 2019 |
91Hemen | CVE-2025-2746Silahlaştırılmış | Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypasskentico · xperience · CWE-288 | Kritik9,8 | KEV | %73,0 | 24 Mar 2025 |
60Bu hafta | CVE-2017-17736Kavram kanıtı | Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/instakentico · xperience · CWE-425 | Kritik9,8 | — | %68,5 | 23 Mar 2018 |
59Planlayın | CVE-2025-2749Silahlaştırılmış | Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCEkentico · xperience · CWE-22 | Yüksek7,2 | KEV | %4,1 | 24 Mar 2025 |
42Planlayın | CVE-2025-2748Kavram kanıtı | Kentico Xperience stored cross-site scripting in multiple-file upload functionalitykentico · xperience · CWE-79 | Orta6,1 | — | %60,6 | 24 Mar 2025 |
40Planlayın | CVE-2021-27581İstismar yok | The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.kentico · kentico cms · CWE-89 | Kritik9,8 | — | %1,7 | 5 Mar 2021 |
39İzleyin | CVE-2025-32370Kavram kanıtı | Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, becauskentico · xperience · CWE-912 | Kritik9,8 | — | %1,5 | 6 Nis 2025 |
37İzleyin | CVE-2019-12102Kavram kanıtı | Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselectkentico · xperience · CWE-732 | Kritik9,1 | — | %2,2 | 22 May 2019 |
35İzleyin | CVE-2018-19453İstismar yok | Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.kentico · xperience · CWE-434 | Yüksek8,8 | — | %1,4 | 10 Nis 2019 |
34İzleyin | CVE-2025-2794İstismar yok | Kentico Xperience <= 13.0.180 Unsafe Reflectionkentico · xperience · CWE-470 | Yüksek8,7 | — | %0,5 | 31 Mar 2025 |
34İzleyin | CVE-2023-53934İstismar yok | Kentico Xperience <= 12.0.98 GetResource Handler Denial of Servicekentico · xperience · CWE-97 | Yüksek8,7 | — | %0,4 | 18 Ara 2025 |
34İzleyin | CVE-2020-36890İstismar yok | Kentico Xperience <= 10 Administrator Access Control Bypasskentico · xperience · CWE-862 | Yüksek8,6 | — | %0,3 | 18 Ara 2025 |
34İzleyin | CVE-2019-25229İstismar yok | Kentico Xperience <= 12.0.29 MVC Forms Unrestricted File Uploadkentico · xperience · CWE-434 | Yüksek8,7 | — | %0,3 | 18 Ara 2025 |
34İzleyin | CVE-2021-47711İstismar yok | Kentico Xperience <= 13.0.52 Online Marketing Macros SQL Injectionkentico · xperience · CWE-89 | Yüksek8,7 | — | %0,3 | 18 Ara 2025 |
31İzleyin | CVE-2018-5282Kavram kanıtı | Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstalkentico · xperience · CWE-787 | Yüksek7,8 | — | %1,5 | 8 Oca 2018 |
30İzleyin | CVE-2018-7046İstismar yok | Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commakentico · xperience · CWE-78 | Yüksek7,2 | — | %5,4 | 20 Şub 2018 |
30İzleyin | CVE-2022-32387İstismar yok | In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler.kentico · xperience | Yüksek7,5 | — | %1,1 | 18 Tem 2022 |
30İzleyin | CVE-2025-5591İstismar yok | Stored Cross-site Scripting (XSS) in Kentico Xperience 13kentico · xperience · CWE-79 | Yüksek7,7 | — | %0,2 | 4 Oca 2026 |
28İzleyin | CVE-2019-6242İstismar yok | Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page.kentico · xperience · CWE-522 | Yüksek7,2 | — | %1,2 | 8 Şub 2019 |
28İzleyin | CVE-2018-6843İstismar yok | Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.kentico · xperience · CWE-89 | Yüksek7,2 | — | %1,1 | 19 Mar 2018 |
27İzleyin | CVE-2022-50686İstismar yok | Kentico Xperience <= 12.0 Portal Engine Form Control Information Disclosurekentico · xperience · CWE-209 | Orta6,9 | — | %0,3 | 18 Ara 2025 |
27İzleyin | CVE-2024-58320İstismar yok | Kentico Xperience <= 13.0.159 Authentication Information Disclosurekentico · xperience · CWE-497 | Orta6,9 | — | %0,3 | 18 Ara 2025 |
27İzleyin | CVE-2021-47712İstismar yok | Kentico Xperience <= 12.0.102 URL Hashing Cryptography Vulnerabilitykentico · xperience · CWE-327 | Orta6,9 | — | %0,2 | 18 Ara 2025 |
27İzleyin | CVE-2022-50682İstismar yok | Kentico Xperience <= 13.0.79 Routing Engine CRLF Injectionkentico · xperience · CWE-93 | Orta6,9 | — | %0,2 | 18 Ara 2025 |
- CVE-2025-274798Hemen
Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97kentico · xperience24 Mar 2025
- CVE-2019-1006898Hemen
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95kentico · xperience26 Mar 2019
- CVE-2025-274691Hemen
Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %73kentico · xperience24 Mar 2025
- CVE-2017-1773660Bu hafta
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/insta
KritikCVSS 9,8Kavram kanıtıEPSS %68kentico · xperience23 Mar 2018
- CVE-2025-274959Planlayın
Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %4kentico · xperience24 Mar 2025
- CVE-2025-274842Planlayın
Kentico Xperience stored cross-site scripting in multiple-file upload functionality
OrtaCVSS 6,1Kavram kanıtıEPSS %61kentico · xperience24 Mar 2025
- CVE-2021-2758140Planlayın
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
KritikCVSS 9,8İstismar yokEPSS %2kentico · kentico cms5 Mar 2021
- CVE-2025-3237039İzleyin
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, becaus
KritikCVSS 9,8Kavram kanıtıEPSS %2kentico · xperience6 Nis 2025
- CVE-2019-1210237İzleyin
Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselect
KritikCVSS 9,1Kavram kanıtıEPSS %2kentico · xperience22 May 2019
- CVE-2018-1945335İzleyin
Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.
YüksekCVSS 8,8İstismar yokEPSS %1kentico · xperience10 Nis 2019
- CVE-2025-279434İzleyin
Kentico Xperience <= 13.0.180 Unsafe Reflection
YüksekCVSS 8,7İstismar yokEPSS %0kentico · xperience31 Mar 2025
- CVE-2023-5393434İzleyin
Kentico Xperience <= 12.0.98 GetResource Handler Denial of Service
YüksekCVSS 8,7İstismar yokEPSS %0kentico · xperience18 Ara 2025
- CVE-2020-3689034İzleyin
Kentico Xperience <= 10 Administrator Access Control Bypass
YüksekCVSS 8,6İstismar yokEPSS %0kentico · xperience18 Ara 2025
- CVE-2019-2522934İzleyin
Kentico Xperience <= 12.0.29 MVC Forms Unrestricted File Upload
YüksekCVSS 8,7İstismar yokEPSS %0kentico · xperience18 Ara 2025
- CVE-2021-4771134İzleyin
Kentico Xperience <= 13.0.52 Online Marketing Macros SQL Injection
YüksekCVSS 8,7İstismar yokEPSS %0kentico · xperience18 Ara 2025
- CVE-2018-528231İzleyin
Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstal
YüksekCVSS 7,8Kavram kanıtıEPSS %2kentico · xperience8 Oca 2018
- CVE-2018-704630İzleyin
Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system comma
YüksekCVSS 7,2İstismar yokEPSS %5kentico · xperience20 Şub 2018
- CVE-2022-3238730İzleyin
In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler.
YüksekCVSS 7,5İstismar yokEPSS %1kentico · xperience18 Tem 2022
- CVE-2025-559130İzleyin
Stored Cross-site Scripting (XSS) in Kentico Xperience 13
YüksekCVSS 7,7İstismar yokEPSS %0kentico · xperience4 Oca 2026
- CVE-2019-624228İzleyin
Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page.
YüksekCVSS 7,2İstismar yokEPSS %1kentico · xperience8 Şub 2019
- CVE-2018-684328İzleyin
Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.
YüksekCVSS 7,2İstismar yokEPSS %1kentico · xperience19 Mar 2018
- CVE-2022-5068627İzleyin
Kentico Xperience <= 12.0 Portal Engine Form Control Information Disclosure
OrtaCVSS 6,9İstismar yokEPSS %0kentico · xperience18 Ara 2025
- CVE-2024-5832027İzleyin
Kentico Xperience <= 13.0.159 Authentication Information Disclosure
OrtaCVSS 6,9İstismar yokEPSS %0kentico · xperience18 Ara 2025
- CVE-2021-4771227İzleyin
Kentico Xperience <= 12.0.102 URL Hashing Cryptography Vulnerability
OrtaCVSS 6,9İstismar yokEPSS %0kentico · xperience18 Ara 2025
- CVE-2022-5068227İzleyin
Kentico Xperience <= 13.0.79 Routing Engine CRLF Injection
OrtaCVSS 6,9İstismar yokEPSS %0kentico · xperience18 Ara 2025