nedi kayıtları
nedi üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-203 Observable Discrepancy1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2021-26753İstismar yok | NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POnedi · nedi · CWE-863 | Kritik9,9 | — | %1,2 | 12 Şub 2021 |
37İzleyin | CVE-2018-20727İstismar yok | Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt panedi · nedi · CWE-78 | Yüksek8,8 | — | %5,6 | 16 Oca 2019 |
37İzleyin | CVE-2022-40895İstismar yok | In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to anedi · nedi · CWE-203 | Kritik9,1 | — | %1,8 | 6 Eki 2022 |
36İzleyin | CVE-2020-14412İstismar yok | NeDi 1.9C is vulnerable to Remote Command Execution.nedi · nedi · CWE-78 | Yüksek8,8 | — | %3,7 | 29 Haz 2020 |
36İzleyin | CVE-2020-14414İstismar yok | NeDi 1.9C is vulnerable to Remote Command Execution.nedi · nedi · CWE-78 | Yüksek8,8 | — | %3,7 | 29 Haz 2020 |
35İzleyin | CVE-2021-26752İstismar yok | NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.phpnedi · nedi · CWE-78 | Yüksek8,8 | — | %1,5 | 12 Şub 2021 |
35İzleyin | CVE-2021-26751İstismar yok | NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.phpnedi · nedi · CWE-89 | Yüksek8,8 | — | %1,2 | 12 Şub 2021 |
35İzleyin | CVE-2018-20728İstismar yok | A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.pnedi · nedi · CWE-352 | Yüksek8,8 | — | %0,6 | 16 Oca 2019 |
30İzleyin | CVE-2018-20730İstismar yok | A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.nedi · nedi · CWE-89 | Yüksek7,5 | — | %1,2 | 16 Oca 2019 |
25İzleyin | CVE-2020-14413Kavram kanıtı | NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php.nedi · nedi · CWE-79 | Orta6,1 | — | %3,4 | 29 Haz 2020 |
24İzleyin | CVE-2018-20731İstismar yok | A stored cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via Unedi · nedi · CWE-79 | Orta6,1 | — | %0,8 | 16 Oca 2019 |
24İzleyin | CVE-2018-20729İstismar yok | A reflected cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML vinedi · nedi · CWE-79 | Orta6,1 | — | %0,8 | 16 Oca 2019 |
24İzleyin | CVE-2020-15017İstismar yok | NeDi 1.9C is vulnerable to reflected cross-site scripting.nedi · nedi · CWE-79 | Orta6,1 | — | %0,6 | 26 Haz 2020 |
24İzleyin | CVE-2020-15016İstismar yok | NeDi 1.9C is vulnerable to reflected cross-site scripting.nedi · nedi · CWE-79 | Orta6,1 | — | %0,6 | 26 Haz 2020 |
21İzleyin | CVE-2020-15032İstismar yok | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Orta5,4 | — | %0,6 | 7 Tem 2020 |
21İzleyin | CVE-2020-15034İstismar yok | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Orta5,4 | — | %0,6 | 7 Tem 2020 |
21İzleyin | CVE-2020-15028İstismar yok | NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Orta5,4 | — | %0,6 | 7 Tem 2020 |
21İzleyin | CVE-2020-15030İstismar yok | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Orta5,4 | — | %0,6 | 7 Tem 2020 |
21İzleyin | CVE-2020-15029İstismar yok | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Orta5,4 | — | %0,6 | 7 Tem 2020 |
21İzleyin | CVE-2020-15031İstismar yok | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Orta5,4 | — | %0,6 | 7 Tem 2020 |
21İzleyin | CVE-2020-15033İstismar yok | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Orta5,4 | — | %0,6 | 7 Tem 2020 |
21İzleyin | CVE-2020-23989İstismar yok | NeDi 1.9C allows pwsec.php oid XSS.nedi · nedi · CWE-79 | Orta5,4 | — | %0,6 | 2 Kas 2020 |
21İzleyin | CVE-2020-15036İstismar yok | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Orta5,4 | — | %0,5 | 7 Tem 2020 |
21İzleyin | CVE-2020-15037İstismar yok | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Orta5,4 | — | %0,5 | 7 Tem 2020 |
21İzleyin | CVE-2020-15035İstismar yok | NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.nedi · nedi · CWE-79 | Orta5,4 | — | %0,5 | 7 Tem 2020 |
- CVE-2021-2675339İzleyin
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP PO
KritikCVSS 9,9İstismar yokEPSS %1nedi · nedi12 Şub 2021
- CVE-2018-2072737İzleyin
Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt pa
YüksekCVSS 8,8İstismar yokEPSS %6nedi · nedi16 Oca 2019
- CVE-2022-4089537İzleyin
In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to a
KritikCVSS 9,1İstismar yokEPSS %2nedi · nedi6 Eki 2022
- CVE-2020-1441236İzleyin
NeDi 1.9C is vulnerable to Remote Command Execution.
YüksekCVSS 8,8İstismar yokEPSS %4nedi · nedi29 Haz 2020
- CVE-2020-1441436İzleyin
NeDi 1.9C is vulnerable to Remote Command Execution.
YüksekCVSS 8,8İstismar yokEPSS %4nedi · nedi29 Haz 2020
- CVE-2021-2675235İzleyin
NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php
YüksekCVSS 8,8İstismar yokEPSS %1nedi · nedi12 Şub 2021
- CVE-2021-2675135İzleyin
NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php
YüksekCVSS 8,8İstismar yokEPSS %1nedi · nedi12 Şub 2021
- CVE-2018-2072835İzleyin
A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.p
YüksekCVSS 8,8İstismar yokEPSS %1nedi · nedi16 Oca 2019
- CVE-2018-2073030İzleyin
A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.
YüksekCVSS 7,5İstismar yokEPSS %1nedi · nedi16 Oca 2019
- CVE-2020-1441325İzleyin
NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php.
OrtaCVSS 6,1Kavram kanıtıEPSS %3nedi · nedi29 Haz 2020
- CVE-2018-2073124İzleyin
A stored cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via U
OrtaCVSS 6,1İstismar yokEPSS %1nedi · nedi16 Oca 2019
- CVE-2018-2072924İzleyin
A reflected cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML vi
OrtaCVSS 6,1İstismar yokEPSS %1nedi · nedi16 Oca 2019
- CVE-2020-1501724İzleyin
NeDi 1.9C is vulnerable to reflected cross-site scripting.
OrtaCVSS 6,1İstismar yokEPSS %1nedi · nedi26 Haz 2020
- CVE-2020-1501624İzleyin
NeDi 1.9C is vulnerable to reflected cross-site scripting.
OrtaCVSS 6,1İstismar yokEPSS %1nedi · nedi26 Haz 2020
- CVE-2020-1503221İzleyin
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
OrtaCVSS 5,4İstismar yokEPSS %1nedi · nedi7 Tem 2020
- CVE-2020-1503421İzleyin
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
OrtaCVSS 5,4İstismar yokEPSS %1nedi · nedi7 Tem 2020
- CVE-2020-1502821İzleyin
NeDi 1.9C is vulnerable to a cross-site scripting (XSS) attack.
OrtaCVSS 5,4İstismar yokEPSS %1nedi · nedi7 Tem 2020
- CVE-2020-1503021İzleyin
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
OrtaCVSS 5,4İstismar yokEPSS %1nedi · nedi7 Tem 2020
- CVE-2020-1502921İzleyin
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
OrtaCVSS 5,4İstismar yokEPSS %1nedi · nedi7 Tem 2020
- CVE-2020-1503121İzleyin
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
OrtaCVSS 5,4İstismar yokEPSS %1nedi · nedi7 Tem 2020
- CVE-2020-1503321İzleyin
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
OrtaCVSS 5,4İstismar yokEPSS %1nedi · nedi7 Tem 2020
- CVE-2020-2398921İzleyin
NeDi 1.9C allows pwsec.php oid XSS.
OrtaCVSS 5,4İstismar yokEPSS %1nedi · nedi2 Kas 2020
- CVE-2020-1503621İzleyin
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
OrtaCVSS 5,4İstismar yokEPSS %1nedi · nedi7 Tem 2020
- CVE-2020-1503721İzleyin
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
OrtaCVSS 5,4İstismar yokEPSS %1nedi · nedi7 Tem 2020
- CVE-2020-1503521İzleyin
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
OrtaCVSS 5,4İstismar yokEPSS %1nedi · nedi7 Tem 2020