İçeriğe atla
Noroxi

pega kayıtları

pega üreticisine ait 50 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%2
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

50 kayıt
  • CVE-2021-27651
    55Planlayın

    In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentica

    KritikCVSS 9,8Kavram kanıtıEPSS %54

    pega · infinity29 Nis 2021

  • CVE-2022-24082
    43Planlayın

    If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filter

    KritikCVSS 9,8Kavram kanıtıEPSS %12

    pega · infinity19 Tem 2022

  • CVE-2019-16374
    40Planlayın

    Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length.

    KritikCVSS 9,8İstismar yokEPSS %2

    pega · platform13 Ağu 2020

  • CVE-2020-15390
    39İzleyin

    pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo

    KritikCVSS 9,8İstismar yokEPSS %1

    pega · pega platform12 Nis 2021

  • CVE-2022-24083
    39İzleyin

    Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

    KritikCVSS 9,8İstismar yokEPSS %1

    pega · infinity25 Tem 2022

  • CVE-2023-32090
    39İzleyin

    Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials

    KritikCVSS 9,8İstismar yokEPSS %1

    pega · pega platform7 Ağu 2023

  • CVE-2023-28094
    39İzleyin

    Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default creden

    KritikCVSS 9,8İstismar yokEPSS %1

    pega · pega platform22 Haz 2023

  • CVE-2024-10094
    39İzleyin

    Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code

    KritikCVSS 9,8İstismar yokEPSS %0

    pega · infinity20 Kas 2024

  • CVE-2020-8775
    35İzleyin

    Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.

    YüksekCVSS 8,9İstismar yokEPSS %1

    pega · platform29 Nis 2020

  • CVE-2020-8773
    35İzleyin

    The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.

    YüksekCVSS 8,9İstismar yokEPSS %1

    pega · platform29 Nis 2020

  • CVE-2020-8774
    35İzleyin

    Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.

    YüksekCVSS 8,8İstismar yokEPSS %1

    pega · pega platform29 Nis 2020

  • CVE-2023-50165
    34İzleyin

    Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

    YüksekCVSS 8,6İstismar yokEPSS %0

    pega · platform31 Oca 2024

  • CVE-2019-16387
    32İzleyin

    PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request

    YüksekCVSS 8,1İstismar yokEPSS %1

    pega · pega platform26 Kas 2019

  • CVE-2021-27654
    31İzleyin

    Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.

    YüksekCVSS 7,8İstismar yokEPSS %1

    pega · infinity28 Oca 2022

  • CVE-2023-26466
    31İzleyin

    A user with non-Admin access can change a configuration file on the client to modify the Server URL.

    YüksekCVSS 7,8İstismar yokEPSS %0

    pega · synchronization engine10 Nis 2023

  • CVE-2023-50168
    30İzleyin

    Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

    YüksekCVSS 7,7İstismar yokEPSS %0

    pega · pega platform14 Mar 2024

  • CVE-2017-11356
    27İzleyin

    The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privil

    OrtaCVSS 6,5Kavram kanıtıEPSS %4

    pega · pega platform2 Ağu 2017

  • CVE-2023-28093
    26İzleyin

    A user with a compromised configuration can start an unsigned binary as a service.

    OrtaCVSS 6,5İstismar yokEPSS %1

    pega · synchronization engine10 Nis 2023

  • CVE-2025-9559
    26İzleyin

    Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to

    OrtaCVSS 6,5İstismar yokEPSS %0

    pega · pega platform16 Eki 2025

  • CVE-2017-11355
    25İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web scri

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    pega · pega platform2 Ağu 2017

  • CVE-2020-23957
    24İzleyin

    Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-T

    OrtaCVSS 6,1İstismar yokEPSS %1

    pega · pega platform15 Ara 2020

  • CVE-2020-24353
    24İzleyin

    Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.

    OrtaCVSS 6,1İstismar yokEPSS %1

    pega · pega platform9 Kas 2020

  • CVE-2022-35654
    24İzleyin

    Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

    OrtaCVSS 6,1İstismar yokEPSS %1

    pega · pega platform22 Ağu 2022

  • CVE-2022-35655
    24İzleyin

    Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.

    OrtaCVSS 6,1İstismar yokEPSS %0

    pega · pega platform22 Ağu 2022

  • CVE-2023-26465
    24İzleyin

    Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.

    OrtaCVSS 6,1İstismar yokEPSS %0

    pega · pega platform9 Haz 2023