İçeriğe atla
Noroxi

Sage kayıtları

sage üreticisine ait 28 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
2 · %7,1
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

28 kayıt
  • CVE-2020-7388
    60Bu hafta

    Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing

    KritikCVSS 9,8SilahlaştırılmışEPSS %69

    sage · adxadmin22 Tem 2021

  • CVE-2022-34324
    39İzleyin

    Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add

    YüksekCVSS 8,8İstismar yokEPSS %12

    sage · sage xrt business exchange1 Oca 2023

  • CVE-2022-41397
    39İzleyin

    The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKe

    KritikCVSS 9,8İstismar yokEPSS %1

    sage · sage 30028 Nis 2023

  • CVE-2022-41400
    39İzleyin

    Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM

    KritikCVSS 9,8İstismar yokEPSS %1

    sage · sage 30028 Nis 2023

  • CVE-2023-2809
    39İzleyin

    Use of Cleartext credentials in Sage 200 Spain

    KritikCVSS 9,8İstismar yokEPSS %0

    sage · sage 200 spain4 Eki 2023

  • CVE-2017-3183
    36İzleyin

    Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full access to pri

    YüksekCVSS 8,8İstismar yokEPSS %2

    sage · xrt treasury24 Tem 2018

  • CVE-2022-34322
    36İzleyin

    Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScript code in the conte

    KritikCVSS 9,0İstismar yokEPSS %1

    sage · sage enterprise intelligence1 Oca 2023

  • CVE-2020-7387
    32İzleyin

    Sage X3 AdxAdmin Exposure of Sensitive Information to an Unauthorized Actor

    OrtaCVSS 5,3SilahlaştırılmışEPSS %36

    sage · adxadmin22 Tem 2021

  • CVE-2024-48646
    32İzleyin

    An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validatio

    YüksekCVSS 8,1İstismar yokEPSS %1

    sage · sage frp 100030 Eki 2024

  • CVE-2021-45492
    31İzleyin

    In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the

    YüksekCVSS 7,8İstismar yokEPSS %0

    sage · sage 30014 Tem 2022

  • CVE-2022-38583
    31İzleyin

    On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configura

    YüksekCVSS 7,8İstismar yokEPSS %0

    sage · sage 30028 Nis 2023

  • CVE-2019-25053
    30İzleyin

    A path traversal vulnerability exists in Sage FRP 1000 before November 2019.

    YüksekCVSS 7,5İstismar yokEPSS %1

    sage · sage frp 100027 Oca 2023

  • CVE-2022-41399
    30İzleyin

    The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decryp

    YüksekCVSS 7,5İstismar yokEPSS %1

    sage · sage 30028 Nis 2023

  • CVE-2022-41398
    30İzleyin

    The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr i

    YüksekCVSS 7,5İstismar yokEPSS %1

    sage · sage 30028 Nis 2023

  • CVE-2020-7389
    29İzleyin

    Sage X3 Syracuse Missing Authentication for Critical Function in Developer Environment

    YüksekCVSS 7,2İstismar yokEPSS %2

    sage · syracuse22 Tem 2021

  • CVE-2006-4712
    28İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Sage 1.3.6 allow remote attackers to inject arbitrary web script or HTML via JavaScri

    OrtaCVSS 6,8İstismar yokEPSS %2

    sage · sage12 Eyl 2006

  • CVE-2024-48647
    28İzleyin

    A file disclosure vulnerability exists in Sage 1000 v7.0.0.

    YüksekCVSS 7,2İstismar yokEPSS %1

    sage · sage frp 100030 Eki 2024

  • CVE-2023-31867
    28İzleyin

    Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.

    YüksekCVSS 7,2İstismar yokEPSS %1

    sage · x322 Haz 2023

  • CVE-2024-48648
    24İzleyin

    A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0.

    OrtaCVSS 6,1İstismar yokEPSS %0

    sage · sage frp 100030 Eki 2024

  • CVE-2003-1242
    22İzleyin

    Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path i

    OrtaCVSS 5,0Kavram kanıtıEPSS %7

    sage · sage31 Ara 2003

  • CVE-2020-7390
    21İzleyin

    Sage X3 Syracuse Persistent XSS in Edit User page

    OrtaCVSS 5,4İstismar yokEPSS %1

    sage · syracuse22 Tem 2021

  • CVE-2020-13893
    21İzleyin

    Multiple stored cross-site scripting (XSS) vulnerabilities in Sage EasyPay 10.7.5.10 allow authenticated attackers to inject arbitrary web s

    OrtaCVSS 5,4İstismar yokEPSS %1

    sage · easypay18 Eki 2020

  • CVE-2022-34323
    21İzleyin

    Multiple XSS issues were discovered in Sage XRT Business Exchange 12.4.302 that allow an attacker to execute JavaScript code in the context

    OrtaCVSS 5,4İstismar yokEPSS %0

    sage · sage xrt business exchange1 Oca 2023

  • CVE-2023-31868
    21İzleyin

    Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS).

    OrtaCVSS 5,4İstismar yokEPSS %0

    sage · x322 Haz 2023

  • CVE-2003-1243
    18İzleyin

    Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter

    OrtaCVSS 4,3Kavram kanıtıEPSS %4

    sage · sage31 Ara 2003