opencats kayıtları
opencats üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-502 Deserialization of Untrusted Data2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2021-41560Kavram kanıtı | OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.opencats · opencats · CWE-434 | Kritik9,8 | — | %11,1 | 15 Ara 2021 |
42Planlayın | CVE-2021-25294İstismar yok | OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution.opencats · opencats · CWE-502 | Kritik9,8 | — | %10,9 | 18 Oca 2021 |
41Planlayın | CVE-2023-27293İstismar yok | Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer opencats · opencats · CWE-79 | Orta6,1 | — | %57,0 | 28 Şub 2023 |
40Planlayın | CVE-2022-43019İstismar yok | OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.opencats · opencats · CWE-502 | Kritik9,8 | — | %2,1 | 19 Eki 2022 |
39İzleyin | CVE-2022-48011İstismar yok | Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.opencats · opencats · CWE-89 | Kritik9,8 | — | %1,1 | 27 Oca 2023 |
37İzleyin | CVE-2019-13358Kavram kanıtı | lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system.opencats · opencats · CWE-611 | Yüksek7,5 | — | %24,3 | 5 Tem 2019 |
26İzleyin | CVE-2022-43022İstismar yok | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.opencats · opencats · CWE-89 | Orta6,5 | — | %0,9 | 19 Eki 2022 |
26İzleyin | CVE-2022-43020İstismar yok | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.opencats · opencats · CWE-89 | Orta6,5 | — | %0,9 | 19 Eki 2022 |
26İzleyin | CVE-2022-43021İstismar yok | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.opencats · opencats · CWE-89 | Orta6,5 | — | %0,9 | 19 Eki 2022 |
26İzleyin | CVE-2022-43023İstismar yok | OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.opencats · opencats · CWE-89 | Orta6,5 | — | %0,9 | 19 Eki 2022 |
24İzleyin | CVE-2021-25295İstismar yok | OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.opencats · opencats · CWE-79 | Orta6,1 | — | %1,5 | 18 Oca 2021 |
24İzleyin | CVE-2022-43016Kavram kanıtı | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.opencats · opencats · CWE-79 | Orta6,1 | — | %1,5 | 19 Eki 2022 |
24İzleyin | CVE-2022-43017Kavram kanıtı | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.opencats · opencats · CWE-79 | Orta6,1 | — | %1,5 | 19 Eki 2022 |
24İzleyin | CVE-2022-43018Kavram kanıtı | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email fuopencats · opencats · CWE-79 | Orta6,1 | — | %1,5 | 19 Eki 2022 |
24İzleyin | CVE-2022-43015Kavram kanıtı | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.opencats · opencats · CWE-79 | Orta6,1 | — | %1,4 | 19 Eki 2022 |
24İzleyin | CVE-2022-43014Kavram kanıtı | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.opencats · opencats · CWE-79 | Orta6,1 | — | %1,4 | 19 Eki 2022 |
24İzleyin | CVE-2022-48012Kavram kanıtı | Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settiopencats · opencats · CWE-79 | Orta6,1 | — | %1,4 | 27 Oca 2023 |
21İzleyin | CVE-2023-27292Kavram kanıtı | An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.opencats · opencats · CWE-601 | Orta5,4 | — | %1,0 | 28 Şub 2023 |
21İzleyin | CVE-2023-27294İstismar yok | Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit mopencats · opencats · CWE-79 | Orta5,4 | — | %0,5 | 28 Şub 2023 |
21İzleyin | CVE-2022-48013İstismar yok | Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar.opencats · opencats · CWE-79 | Orta5,4 | — | %0,5 | 27 Oca 2023 |
21İzleyin | CVE-2023-26847İstismar yok | A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a craftedopencats · opencats · CWE-79 | Orta5,4 | — | %0,4 | 11 Nis 2023 |
21İzleyin | CVE-2023-26846İstismar yok | A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a craftedopencats · opencats · CWE-79 | Orta5,4 | — | %0,4 | 11 Nis 2023 |
21İzleyin | CVE-2023-27295İstismar yok | Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests.opencats · opencats · CWE-352 | Orta5,4 | — | %0,4 | 28 Şub 2023 |
17İzleyin | CVE-2023-26845İstismar yok | A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.opencats · opencats · CWE-352 | Orta4,3 | — | %0,2 | 11 Nis 2023 |
- CVE-2021-4156042Planlayın
OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.
KritikCVSS 9,8Kavram kanıtıEPSS %11opencats · opencats15 Ara 2021
- CVE-2021-2529442Planlayın
OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution.
KritikCVSS 9,8İstismar yokEPSS %11opencats · opencats18 Oca 2021
- CVE-2023-2729341Planlayın
Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer
OrtaCVSS 6,1İstismar yokEPSS %57opencats · opencats28 Şub 2023
- CVE-2022-4301940Planlayın
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.
KritikCVSS 9,8İstismar yokEPSS %2opencats · opencats19 Eki 2022
- CVE-2022-4801139İzleyin
Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
KritikCVSS 9,8İstismar yokEPSS %1opencats · opencats27 Oca 2023
- CVE-2019-1335837İzleyin
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system.
YüksekCVSS 7,5Kavram kanıtıEPSS %24opencats · opencats5 Tem 2019
- CVE-2022-4302226İzleyin
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.
OrtaCVSS 6,5İstismar yokEPSS %1opencats · opencats19 Eki 2022
- CVE-2022-4302026İzleyin
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.
OrtaCVSS 6,5İstismar yokEPSS %1opencats · opencats19 Eki 2022
- CVE-2022-4302126İzleyin
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.
OrtaCVSS 6,5İstismar yokEPSS %1opencats · opencats19 Eki 2022
- CVE-2022-4302326İzleyin
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
OrtaCVSS 6,5İstismar yokEPSS %1opencats · opencats19 Eki 2022
- CVE-2021-2529524İzleyin
OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.
OrtaCVSS 6,1İstismar yokEPSS %2opencats · opencats18 Oca 2021
- CVE-2022-4301624İzleyin
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.
OrtaCVSS 6,1Kavram kanıtıEPSS %1opencats · opencats19 Eki 2022
- CVE-2022-4301724İzleyin
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.
OrtaCVSS 6,1Kavram kanıtıEPSS %1opencats · opencats19 Eki 2022
- CVE-2022-4301824İzleyin
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email fu
OrtaCVSS 6,1Kavram kanıtıEPSS %1opencats · opencats19 Eki 2022
- CVE-2022-4301524İzleyin
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %1opencats · opencats19 Eki 2022
- CVE-2022-4301424İzleyin
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %1opencats · opencats19 Eki 2022
- CVE-2022-4801224İzleyin
Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=setti
OrtaCVSS 6,1Kavram kanıtıEPSS %1opencats · opencats27 Oca 2023
- CVE-2023-2729221İzleyin
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.
OrtaCVSS 5,4Kavram kanıtıEPSS %1opencats · opencats28 Şub 2023
- CVE-2023-2729421İzleyin
Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit m
OrtaCVSS 5,4İstismar yokEPSS %1opencats · opencats28 Şub 2023
- CVE-2022-4801321İzleyin
Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar.
OrtaCVSS 5,4İstismar yokEPSS %1opencats · opencats27 Oca 2023
- CVE-2023-2684721İzleyin
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted
OrtaCVSS 5,4İstismar yokEPSS %0opencats · opencats11 Nis 2023
- CVE-2023-2684621İzleyin
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted
OrtaCVSS 5,4İstismar yokEPSS %0opencats · opencats11 Nis 2023
- CVE-2023-2729521İzleyin
Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests.
OrtaCVSS 5,4İstismar yokEPSS %0opencats · opencats28 Şub 2023
- CVE-2023-2684517İzleyin
A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.
OrtaCVSS 4,3İstismar yokEPSS %0opencats · opencats11 Nis 2023