microweber kayıtları
microweber üreticisine ait 115 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,9
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %65,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')57
- CWE-434 Unrestricted Upload of File with Dangerous Type7
- CWE-190 Integer Overflow or Wraparound4
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-840 Business Logic Errors4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
115 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2022-0557Kavram kanıtı | OS Command Injection in microweber/microwebermicroweber · microweber · CWE-78 | Yüksek7,2 | — | %51,2 | 11 Şub 2022 |
43Planlayın | CVE-2022-0666Kavram kanıtı | CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microwebermicroweber · microweber · CWE-93 | Yüksek7,5 | — | %44,3 | 18 Şub 2022 |
40Planlayın | CVE-2023-1877İstismar yok | Command Injection in microweber/microwebermicroweber · microweber · CWE-77 | Kritik9,8 | — | %1,8 | 5 Nis 2023 |
40Planlayın | CVE-2022-0895İstismar yok | Static Code Injection in microweber/microwebermicroweber · microweber · CWE-96 | Kritik9,8 | — | %1,7 | 10 Mar 2022 |
39İzleyin | CVE-2022-4732İstismar yok | Unrestricted Upload of File with Dangerous Type in microweber/microwebermicroweber · microweber · CWE-434 | Yüksek7,2 | — | %38,2 | 27 Ara 2022 |
39İzleyin | CVE-2020-23138İstismar yok | An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page.microweber · microweber · CWE-434 | Kritik9,8 | — | %1,3 | 9 Kas 2020 |
39İzleyin | CVE-2022-2368İstismar yok | Authentication Bypass by Spoofing in microweber/microwebermicroweber · microweber · CWE-290 | Kritik9,8 | — | %1,2 | 11 Tem 2022 |
38İzleyin | CVE-2022-1631Kavram kanıtı | Users Account Pre-Takeover or Users Account Takeover. in microweber/microwebermicroweber · microweber · CWE-284 | Yüksek8,8 | — | %8,9 | 9 May 2022 |
36İzleyin | CVE-2023-49052Kavram kanıtı | File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload fmicroweber · microweber · CWE-434 | Yüksek8,8 | — | %2,4 | 30 Kas 2023 |
35İzleyin | CVE-2022-33012İstismar yok | Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.microweber · microweber · CWE-74 | Yüksek8,8 | — | %1,4 | 22 Kas 2022 |
35İzleyin | CVE-2022-0896İstismar yok | Improper Neutralization of Special Elements Used in a Template Engine in microweber/microwebermicroweber · microweber · CWE-1336 | Yüksek8,8 | — | %1,4 | 9 Mar 2022 |
35İzleyin | CVE-2021-36461İstismar yok | An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section microweber · microweber · CWE-434 | Yüksek8,8 | — | %0,9 | 15 Tem 2022 |
35İzleyin | CVE-2018-17104İstismar yok | An issue was discovered in Microweber 1.0.7.microweber · microweber · CWE-352 | Yüksek8,8 | — | %0,8 | 16 Eyl 2018 |
35İzleyin | CVE-2023-2240İstismar yok | Improper Privilege Management in microweber/microwebermicroweber · microweber · CWE-269 | Yüksek8,8 | — | %0,7 | 21 Nis 2023 |
34İzleyin | CVE-2020-13405Kavram kanıtı | userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database microweber · microweber · CWE-306 | Yüksek7,5 | — | %13,6 | 16 Tem 2020 |
33İzleyin | CVE-2020-28337Kavram kanıtı | A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execmicroweber · microweber · CWE-22 | Yüksek7,2 | — | %16,6 | 15 Şub 2021 |
33İzleyin | CVE-2022-0281Kavram kanıtı | Exposure of Sensitive Information to an Unauthorized Actor in microweber/microwebermicroweber · microweber · CWE-200 | Yüksek7,5 | — | %10,5 | 20 Oca 2022 |
33İzleyin | CVE-2025-60954İstismar yok | Microweber CMS 2.0 has Weak Password Requirements.microweber · microweber · CWE-521 | Yüksek8,3 | — | %0,5 | 24 Eki 2025 |
32İzleyin | CVE-2022-0660Kavram kanıtı | Generation of Error Message Containing Sensitive Information in microweber/microwebermicroweber · microweber · CWE-209 | Yüksek7,5 | — | %6,9 | 18 Şub 2022 |
32İzleyin | CVE-2020-23140İstismar yok | Microweber 1.1.18 is affected by insufficient session expiration.microweber · microweber · CWE-613 | Yüksek8,1 | — | %1,0 | 9 Kas 2020 |
31İzleyin | CVE-2014-9464Kavram kanıtı | SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commandsmicroweber · microweber · CWE-89 | Yüksek7,5 | — | %2,1 | 3 Oca 2015 |
31İzleyin | CVE-2020-13241İstismar yok | Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extmicroweber · microweber · CWE-434 | Yüksek7,8 | — | %0,5 | 20 May 2020 |
30İzleyin | CVE-2022-0913İstismar yok | Integer Overflow or Wraparound in microweber/microwebermicroweber · microweber · CWE-190 | Yüksek7,5 | — | %1,4 | 11 Mar 2022 |
30İzleyin | CVE-2022-0282İstismar yok | Cross-site Scripting in microweber/microwebermicroweber · microweber · CWE-79 | Yüksek7,5 | — | %1,4 | 20 Oca 2022 |
30İzleyin | CVE-2022-0777İstismar yok | Weak Password Recovery Mechanism for Forgotten Password in microweber/microwebermicroweber · microweber · CWE-640 | Yüksek7,5 | — | %1,2 | 1 Mar 2022 |
- CVE-2022-055743Planlayın
OS Command Injection in microweber/microweber
YüksekCVSS 7,2Kavram kanıtıEPSS %51microweber · microweber11 Şub 2022
- CVE-2022-066643Planlayın
CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
YüksekCVSS 7,5Kavram kanıtıEPSS %44microweber · microweber18 Şub 2022
- CVE-2023-187740Planlayın
Command Injection in microweber/microweber
KritikCVSS 9,8İstismar yokEPSS %2microweber · microweber5 Nis 2023
- CVE-2022-089540Planlayın
Static Code Injection in microweber/microweber
KritikCVSS 9,8İstismar yokEPSS %2microweber · microweber10 Mar 2022
- CVE-2022-473239İzleyin
Unrestricted Upload of File with Dangerous Type in microweber/microweber
YüksekCVSS 7,2İstismar yokEPSS %38microweber · microweber27 Ara 2022
- CVE-2020-2313839İzleyin
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page.
KritikCVSS 9,8İstismar yokEPSS %1microweber · microweber9 Kas 2020
- CVE-2022-236839İzleyin
Authentication Bypass by Spoofing in microweber/microweber
KritikCVSS 9,8İstismar yokEPSS %1microweber · microweber11 Tem 2022
- CVE-2022-163138İzleyin
Users Account Pre-Takeover or Users Account Takeover. in microweber/microweber
YüksekCVSS 8,8Kavram kanıtıEPSS %9microweber · microweber9 May 2022
- CVE-2023-4905236İzleyin
File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload f
YüksekCVSS 8,8Kavram kanıtıEPSS %2microweber · microweber30 Kas 2023
- CVE-2022-3301235İzleyin
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
YüksekCVSS 8,8İstismar yokEPSS %1microweber · microweber22 Kas 2022
- CVE-2022-089635İzleyin
Improper Neutralization of Special Elements Used in a Template Engine in microweber/microweber
YüksekCVSS 8,8İstismar yokEPSS %1microweber · microweber9 Mar 2022
- CVE-2021-3646135İzleyin
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section
YüksekCVSS 8,8İstismar yokEPSS %1microweber · microweber15 Tem 2022
- CVE-2018-1710435İzleyin
An issue was discovered in Microweber 1.0.7.
YüksekCVSS 8,8İstismar yokEPSS %1microweber · microweber16 Eyl 2018
- CVE-2023-224035İzleyin
Improper Privilege Management in microweber/microweber
YüksekCVSS 8,8İstismar yokEPSS %1microweber · microweber21 Nis 2023
- CVE-2020-1340534İzleyin
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database
YüksekCVSS 7,5Kavram kanıtıEPSS %14microweber · microweber16 Tem 2020
- CVE-2020-2833733İzleyin
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code exec
YüksekCVSS 7,2Kavram kanıtıEPSS %17microweber · microweber15 Şub 2021
- CVE-2022-028133İzleyin
Exposure of Sensitive Information to an Unauthorized Actor in microweber/microweber
YüksekCVSS 7,5Kavram kanıtıEPSS %10microweber · microweber20 Oca 2022
- CVE-2025-6095433İzleyin
Microweber CMS 2.0 has Weak Password Requirements.
YüksekCVSS 8,3İstismar yokEPSS %0microweber · microweber24 Eki 2025
- CVE-2022-066032İzleyin
Generation of Error Message Containing Sensitive Information in microweber/microweber
YüksekCVSS 7,5Kavram kanıtıEPSS %7microweber · microweber18 Şub 2022
- CVE-2020-2314032İzleyin
Microweber 1.1.18 is affected by insufficient session expiration.
YüksekCVSS 8,1İstismar yokEPSS %1microweber · microweber9 Kas 2020
- CVE-2014-946431İzleyin
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %2microweber · microweber3 Oca 2015
- CVE-2020-1324131İzleyin
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file ext
YüksekCVSS 7,8İstismar yokEPSS %0microweber · microweber20 May 2020
- CVE-2022-091330İzleyin
Integer Overflow or Wraparound in microweber/microweber
YüksekCVSS 7,5İstismar yokEPSS %1microweber · microweber11 Mar 2022
- CVE-2022-028230İzleyin
Cross-site Scripting in microweber/microweber
YüksekCVSS 7,5İstismar yokEPSS %1microweber · microweber20 Oca 2022
- CVE-2022-077730İzleyin
Weak Password Recovery Mechanism for Forgotten Password in microweber/microweber
YüksekCVSS 7,5İstismar yokEPSS %1microweber · microweber1 Mar 2022