MITRE kayıtları
mitre üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %6,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-269 Improper Privilege Management1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2021-42561Kavram kanıtı | An issue was discovered in CALDERA 2.8.1.mitre · caldera · CWE-74 | Yüksek8,8 | — | %19,6 | 12 Oca 2022 |
41Planlayın | CVE-2008-4704Kavram kanıtı | PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via mitre · sezhoo · CWE-94 | Kritik10,0 | — | %3,5 | 23 Eki 2008 |
36İzleyin | CVE-2020-19907İstismar yok | A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command omitre · caldera · CWE-78 | Yüksek8,8 | — | %3,0 | 12 Tem 2021 |
36İzleyin | CVE-2021-42560Kavram kanıtı | An issue was discovered in CALDERA 2.9.0.mitre · caldera · CWE-611 | Yüksek8,8 | — | %2,1 | 12 Oca 2022 |
36İzleyin | CVE-2021-42559Kavram kanıtı | An issue was discovered in CALDERA 2.8.1.mitre · caldera · CWE-77 | Yüksek8,8 | — | %2,0 | 12 Oca 2022 |
32İzleyin | CVE-2021-42562Kavram kanıtı | An issue was discovered in CALDERA 2.8.1.mitre · caldera · CWE-269 | Yüksek8,1 | — | %1,2 | 12 Oca 2022 |
30İzleyin | CVE-2022-31004İstismar yok | Potential secrets being logged to disk in CVE Servicesmitre · cve-services · CWE-779 | Yüksek7,5 | — | %1,0 | 2 Haz 2022 |
28İzleyin | CVE-2021-46561İstismar yok | controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizamitre · cve services · CWE-863 | Yüksek7,2 | — | %0,8 | 26 Oca 2022 |
24İzleyin | CVE-2021-42558Kavram kanıtı | An issue was discovered in CALDERA 2.8.1.mitre · caldera · CWE-79 | Orta6,1 | — | %1,1 | 12 Oca 2022 |
24İzleyin | CVE-2022-40606İstismar yok | MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability thmitre · caldera · CWE-79 | Orta6,1 | — | %0,5 | 17 Eki 2022 |
24İzleyin | CVE-2022-40605İstismar yok | MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability thmitre · caldera · CWE-79 | Orta6,1 | — | %0,5 | 17 Eki 2022 |
21İzleyin | CVE-2020-10807İstismar yok | auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host heademitre · caldera · CWE-290 | Orta5,3 | — | %1,4 | 22 Mar 2020 |
21İzleyin | CVE-2020-14462İstismar yok | CALDERA 2.7.0 allows XSS via the Operation Name box.mitre · caldera · CWE-79 | Orta5,4 | — | %0,6 | 19 Haz 2020 |
21İzleyin | CVE-2022-41139İstismar yok | MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commitre · caldera · CWE-79 | Orta5,4 | — | %0,6 | 17 Eki 2022 |
13İzleyin | CVE-2023-51792İstismar yok | Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding theCWE-121 | Düşük3,3 | — | %0,2 | 19 Nis 2024 |
- CVE-2021-4256141Planlayın
An issue was discovered in CALDERA 2.8.1.
YüksekCVSS 8,8Kavram kanıtıEPSS %20mitre · caldera12 Oca 2022
- CVE-2008-470441Planlayın
PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via
KritikCVSS 10,0Kavram kanıtıEPSS %4mitre · sezhoo23 Eki 2008
- CVE-2020-1990736İzleyin
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command o
YüksekCVSS 8,8İstismar yokEPSS %3mitre · caldera12 Tem 2021
- CVE-2021-4256036İzleyin
An issue was discovered in CALDERA 2.9.0.
YüksekCVSS 8,8Kavram kanıtıEPSS %2mitre · caldera12 Oca 2022
- CVE-2021-4255936İzleyin
An issue was discovered in CALDERA 2.8.1.
YüksekCVSS 8,8Kavram kanıtıEPSS %2mitre · caldera12 Oca 2022
- CVE-2021-4256232İzleyin
An issue was discovered in CALDERA 2.8.1.
YüksekCVSS 8,1Kavram kanıtıEPSS %1mitre · caldera12 Oca 2022
- CVE-2022-3100430İzleyin
Potential secrets being logged to disk in CVE Services
YüksekCVSS 7,5İstismar yokEPSS %1mitre · cve-services2 Haz 2022
- CVE-2021-4656128İzleyin
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organiza
YüksekCVSS 7,2İstismar yokEPSS %1mitre · cve services26 Oca 2022
- CVE-2021-4255824İzleyin
An issue was discovered in CALDERA 2.8.1.
OrtaCVSS 6,1Kavram kanıtıEPSS %1mitre · caldera12 Oca 2022
- CVE-2022-4060624İzleyin
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability th
OrtaCVSS 6,1İstismar yokEPSS %0mitre · caldera17 Eki 2022
- CVE-2022-4060524İzleyin
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability th
OrtaCVSS 6,1İstismar yokEPSS %0mitre · caldera17 Eki 2022
- CVE-2020-1080721İzleyin
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host heade
OrtaCVSS 5,3İstismar yokEPSS %1mitre · caldera22 Mar 2020
- CVE-2020-1446221İzleyin
CALDERA 2.7.0 allows XSS via the Operation Name box.
OrtaCVSS 5,4İstismar yokEPSS %1mitre · caldera19 Haz 2020
- CVE-2022-4113921İzleyin
MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary com
OrtaCVSS 5,4İstismar yokEPSS %1mitre · caldera17 Eki 2022
- CVE-2023-5179213İzleyin
Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the
DüşükCVSS 3,3İstismar yokEPSS %019 Nis 2024