qualitor kayıtları
qualitor üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %16,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2024-44849Kavram kanıtı | Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.qualitor · qualitor · CWE-434 | Kritik9,8 | — | %46,3 | 9 Eyl 2024 |
43Planlayın | CVE-2023-47253Kavram kanıtı | Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.phqualitor · qualitor · CWE-77 | Kritik9,8 | — | %14,3 | 6 Kas 2023 |
40Planlayın | CVE-2024-48359Kavram kanıtı | Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.qualitor · qualitor · CWE-94 | Kritik9,8 | — | %2,3 | 31 Eki 2024 |
31İzleyin | CVE-2024-48360Kavram kanıtı | Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.qualitor · qualitor · CWE-918 | Yüksek7,5 | — | %3,9 | 31 Eki 2024 |
12İzleyin | CVE-2025-5139İstismar yok | Qualitor Office 365-type Connection testaConexaoOffice365.php command injectionqualitor · qualitor · CWE-74 | Düşük2,9 | — | %2,6 | 24 May 2025 |
8İzleyin | CVE-2025-14580İstismar yok | Qualitor viewDocumento.php cross site scriptingqualitor · qualitor · CWE-79 | Düşük2,0 | — | %0,3 | 12 Ara 2025 |
- CVE-2024-4484953Planlayın
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
KritikCVSS 9,8Kavram kanıtıEPSS %46qualitor · qualitor9 Eyl 2024
- CVE-2023-4725343Planlayın
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.ph
KritikCVSS 9,8Kavram kanıtıEPSS %14qualitor · qualitor6 Kas 2023
- CVE-2024-4835940Planlayın
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %2qualitor · qualitor31 Eki 2024
- CVE-2024-4836031İzleyin
Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.
YüksekCVSS 7,5Kavram kanıtıEPSS %4qualitor · qualitor31 Eki 2024
- CVE-2025-513912İzleyin
Qualitor Office 365-type Connection testaConexaoOffice365.php command injection
DüşükCVSS 2,9İstismar yokEPSS %3qualitor · qualitor24 May 2025
- CVE-2025-145808İzleyin
Qualitor viewDocumento.php cross site scripting
DüşükCVSS 2,0İstismar yokEPSS %0qualitor · qualitor12 Ara 2025