İçeriğe atla
Noroxi

microweber kayıtları

microweber üreticisine ait 115 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %0,9
Pre-auth RCE
9
Düzeltme kaydı olan
%65,2
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

115 kayıt
  • CVE-2022-0557
    43Planlayın

    OS Command Injection in microweber/microweber

    YüksekCVSS 7,2Kavram kanıtıEPSS %51

    microweber · microweber11 Şub 2022

  • CVE-2022-0666
    43Planlayın

    CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber

    YüksekCVSS 7,5Kavram kanıtıEPSS %44

    microweber · microweber18 Şub 2022

  • CVE-2023-1877
    40Planlayın

    Command Injection in microweber/microweber

    KritikCVSS 9,8İstismar yokEPSS %2

    microweber · microweber5 Nis 2023

  • CVE-2022-0895
    40Planlayın

    Static Code Injection in microweber/microweber

    KritikCVSS 9,8İstismar yokEPSS %2

    microweber · microweber10 Mar 2022

  • CVE-2022-4732
    39İzleyin

    Unrestricted Upload of File with Dangerous Type in microweber/microweber

    YüksekCVSS 7,2İstismar yokEPSS %38

    microweber · microweber27 Ara 2022

  • CVE-2020-23138
    39İzleyin

    An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page.

    KritikCVSS 9,8İstismar yokEPSS %1

    microweber · microweber9 Kas 2020

  • CVE-2022-2368
    39İzleyin

    Authentication Bypass by Spoofing in microweber/microweber

    KritikCVSS 9,8İstismar yokEPSS %1

    microweber · microweber11 Tem 2022

  • CVE-2022-1631
    38İzleyin

    Users Account Pre-Takeover or Users Account Takeover. in microweber/microweber

    YüksekCVSS 8,8Kavram kanıtıEPSS %9

    microweber · microweber9 May 2022

  • CVE-2023-49052
    36İzleyin

    File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload f

    YüksekCVSS 8,8Kavram kanıtıEPSS %2

    microweber · microweber30 Kas 2023

  • CVE-2022-33012
    35İzleyin

    Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

    YüksekCVSS 8,8İstismar yokEPSS %1

    microweber · microweber22 Kas 2022

  • CVE-2022-0896
    35İzleyin

    Improper Neutralization of Special Elements Used in a Template Engine in microweber/microweber

    YüksekCVSS 8,8İstismar yokEPSS %1

    microweber · microweber9 Mar 2022

  • CVE-2021-36461
    35İzleyin

    An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section

    YüksekCVSS 8,8İstismar yokEPSS %1

    microweber · microweber15 Tem 2022

  • CVE-2018-17104
    35İzleyin

    An issue was discovered in Microweber 1.0.7.

    YüksekCVSS 8,8İstismar yokEPSS %1

    microweber · microweber16 Eyl 2018

  • CVE-2023-2240
    35İzleyin

    Improper Privilege Management in microweber/microweber

    YüksekCVSS 8,8İstismar yokEPSS %1

    microweber · microweber21 Nis 2023

  • CVE-2020-13405
    34İzleyin

    userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database

    YüksekCVSS 7,5Kavram kanıtıEPSS %14

    microweber · microweber16 Tem 2020

  • CVE-2020-28337
    33İzleyin

    A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code exec

    YüksekCVSS 7,2Kavram kanıtıEPSS %17

    microweber · microweber15 Şub 2021

  • CVE-2022-0281
    33İzleyin

    Exposure of Sensitive Information to an Unauthorized Actor in microweber/microweber

    YüksekCVSS 7,5Kavram kanıtıEPSS %10

    microweber · microweber20 Oca 2022

  • CVE-2025-60954
    33İzleyin

    Microweber CMS 2.0 has Weak Password Requirements.

    YüksekCVSS 8,3İstismar yokEPSS %0

    microweber · microweber24 Eki 2025

  • CVE-2022-0660
    32İzleyin

    Generation of Error Message Containing Sensitive Information in microweber/microweber

    YüksekCVSS 7,5Kavram kanıtıEPSS %7

    microweber · microweber18 Şub 2022

  • CVE-2020-23140
    32İzleyin

    Microweber 1.1.18 is affected by insufficient session expiration.

    YüksekCVSS 8,1İstismar yokEPSS %1

    microweber · microweber9 Kas 2020

  • CVE-2014-9464
    31İzleyin

    SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    microweber · microweber3 Oca 2015

  • CVE-2020-13241
    31İzleyin

    Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file ext

    YüksekCVSS 7,8İstismar yokEPSS %0

    microweber · microweber20 May 2020

  • CVE-2022-0913
    30İzleyin

    Integer Overflow or Wraparound in microweber/microweber

    YüksekCVSS 7,5İstismar yokEPSS %1

    microweber · microweber11 Mar 2022

  • CVE-2022-0282
    30İzleyin

    Cross-site Scripting in microweber/microweber

    YüksekCVSS 7,5İstismar yokEPSS %1

    microweber · microweber20 Oca 2022

  • CVE-2022-0777
    30İzleyin

    Weak Password Recovery Mechanism for Forgotten Password in microweber/microweber

    YüksekCVSS 7,5İstismar yokEPSS %1

    microweber · microweber1 Mar 2022