simple-help kayıtları
simple-help üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 4 · %66,7
- Silahlaştırılmış
- 4 · %66,7
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- 247 gün
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
89Hemen | CVE-2024-57727Silahlaştırılmış | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated resimple-help · simplehelp · CWE-22 | Yüksek7,5 | KEV | %96,6 | 15 Oca 2025 |
89Hemen | CVE-2024-57726Silahlaştırılmış | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excesimple-help · simplehelp · CWE-862 | Kritik9,9 | KEV | %66,6 | 15 Oca 2025 |
77Bu hafta | CVE-2024-57728Silahlaştırılmış | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading asimple-help · simplehelp · CWE-59 | Yüksek7,2 | KEV | %64,7 | 15 Oca 2025 |
70Bu hafta | CVE-2026-48558Silahlaştırılmış | SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verificationsimple-help · simplehelp · CWE-347 | Kritik9,5 | KEV | %5,7 | 12 Haz 2026 |
35İzleyin | CVE-2025-36727İstismar yok | SimpleHelp Inclusion of functionality from untrusted control spheresimple-help · simplehelp · CWE-829 | Yüksek8,8 | — | %0,4 | 25 Tem 2025 |
35İzleyin | CVE-2025-36728İstismar yok | SimpleHelp Cross Site Request Forgerysimple-help · simplehelp · CWE-352 | Yüksek8,8 | — | %0,2 | 25 Tem 2025 |
- CVE-2024-5772789Hemen
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated re
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %97simple-help · simplehelp15 Oca 2025
- CVE-2024-5772689Hemen
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with exce
KritikCVSS 9,9KEVSilahlaştırılmışEPSS %67simple-help · simplehelp15 Oca 2025
- CVE-2024-5772877Bu hafta
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %65simple-help · simplehelp15 Oca 2025
- CVE-2026-4855870Bu hafta
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
KritikCVSS 9,5KEVSilahlaştırılmışEPSS %6simple-help · simplehelp12 Haz 2026
- CVE-2025-3672735İzleyin
SimpleHelp Inclusion of functionality from untrusted control sphere
YüksekCVSS 8,8İstismar yokEPSS %0simple-help · simplehelp25 Tem 2025
- CVE-2025-3672835İzleyin
SimpleHelp Cross Site Request Forgery
YüksekCVSS 8,8İstismar yokEPSS %0simple-help · simplehelp25 Tem 2025