rws kayıtları
rws üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-287 Improper Authentication1
- CWE-331 Insufficient Entropy1
- CWE-284 Improper Access Control1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2022-34267Kavram kanıtı | An issue was discovered in RWS WorldServer before 11.7.3.rws · worldserver · CWE-287 | Kritik9,8 | — | %42,2 | 25 Ara 2023 |
39İzleyin | CVE-2022-34268İstismar yok | An issue was discovered in RWS WorldServer before 11.7.3.rws · worldserver · CWE-502 | Kritik9,8 | — | %1,5 | 25 Ara 2023 |
39İzleyin | CVE-2022-34270İstismar yok | An issue was discovered in RWS WorldServer before 11.7.3.rws · worldserver · CWE-284 | Kritik9,8 | — | %0,9 | 28 Şub 2024 |
36İzleyin | CVE-2022-34269İstismar yok | An issue was discovered in RWS WorldServer before 11.7.3.rws · worldserver · CWE-918 | Yüksek8,8 | — | %1,7 | 28 Şub 2024 |
30İzleyin | CVE-2005-4548İstismar yok | SQL injection vulnerability in the "user area" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL commarws · statistics counter | Yüksek7,5 | — | %1,2 | 28 Ara 2005 |
26İzleyin | CVE-2024-50848Kavram kanıtı | An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to accerws · worldserver · CWE-611 | Orta6,5 | — | %1,2 | 18 Kas 2024 |
24İzleyin | CVE-2024-43024İstismar yok | Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary wrws · multitrans · CWE-79 | Orta6,1 | — | %0,3 | 18 Eyl 2024 |
24İzleyin | CVE-2024-43025İstismar yok | An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a rws · multitrans · CWE-79 | Orta6,1 | — | %0,3 | 18 Eyl 2024 |
23İzleyin | CVE-2023-38357Kavram kanıtı | Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessiorws · worldserver · CWE-331 | Orta5,3 | — | %5,3 | 1 Ağu 2023 |
19İzleyin | CVE-2024-50849Kavram kanıtı | A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attackerrws · worldserver · CWE-79 | Orta4,8 | — | %0,5 | 18 Kas 2024 |
- CVE-2022-3426752Planlayın
An issue was discovered in RWS WorldServer before 11.7.3.
KritikCVSS 9,8Kavram kanıtıEPSS %42rws · worldserver25 Ara 2023
- CVE-2022-3426839İzleyin
An issue was discovered in RWS WorldServer before 11.7.3.
KritikCVSS 9,8İstismar yokEPSS %1rws · worldserver25 Ara 2023
- CVE-2022-3427039İzleyin
An issue was discovered in RWS WorldServer before 11.7.3.
KritikCVSS 9,8İstismar yokEPSS %1rws · worldserver28 Şub 2024
- CVE-2022-3426936İzleyin
An issue was discovered in RWS WorldServer before 11.7.3.
YüksekCVSS 8,8İstismar yokEPSS %2rws · worldserver28 Şub 2024
- CVE-2005-454830İzleyin
SQL injection vulnerability in the "user area" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL comma
YüksekCVSS 7,5İstismar yokEPSS %1rws · statistics counter28 Ara 2005
- CVE-2024-5084826İzleyin
An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to acce
OrtaCVSS 6,5Kavram kanıtıEPSS %1rws · worldserver18 Kas 2024
- CVE-2024-4302424İzleyin
Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary w
OrtaCVSS 6,1İstismar yokEPSS %0rws · multitrans18 Eyl 2024
- CVE-2024-4302524İzleyin
An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a
OrtaCVSS 6,1İstismar yokEPSS %0rws · multitrans18 Eyl 2024
- CVE-2023-3835723İzleyin
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessio
OrtaCVSS 5,3Kavram kanıtıEPSS %5rws · worldserver1 Ağu 2023
- CVE-2024-5084919İzleyin
A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attacker
OrtaCVSS 4,8Kavram kanıtıEPSS %0rws · worldserver18 Kas 2024