smartertools kayıtları
smartertools üreticisine ait 52 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 3 · %5,8
- Silahlaştırılmış
- 4 · %7,7
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %5,8
- Yayından KEV’e ortanca
- 13 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-306 Missing Authentication for Critical Function1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
52 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
96Hemen | CVE-2026-23760Silahlaştırılmış | SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset APIsmartertools · smartermail · CWE-288 | Kritik9,3 | KEV | %96,5 | 22 Oca 2026 |
96Hemen | CVE-2025-52691Silahlaştırılmış | Upload Arbitrary Filessmartertools · smartermail · CWE-434 | Kritik10,0 | KEV | %85,7 | 28 Ara 2025 |
93Hemen | CVE-2026-24423Silahlaştırılmış | SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub APIsmartertools · smartermail · CWE-306 | Kritik9,3 | KEV | %88,2 | 23 Oca 2026 |
64Bu hafta | CVE-2019-7214Silahlaştırılmış | SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data.smartertools · smartermail · CWE-502 | Kritik9,8 | — | %84,8 | 24 Nis 2019 |
42Planlayın | CVE-2011-2148İstismar yok | Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involvismartertools · smarterstats · CWE-78 | Kritik10,0 | — | %5,3 | 20 May 2011 |
41Planlayın | CVE-2011-2158İstismar yok | The SmarterTools SmarterStats 6.0 web server sends incorrect Content-Type headers for certain resources, which might allow remote attackers smartertools · smarterstats | Kritik10,0 | — | %4,4 | 20 May 2011 |
41Planlayın | CVE-2011-2159İstismar yok | The SmarterTools SmarterStats 6.0 web server omits the Content-Type header for certain resources, which might allow remote attackers to havesmartertools · smarterstats | Kritik10,0 | — | %4,4 | 20 May 2011 |
41Planlayın | CVE-2011-4752İstismar yok | SmarterTools SmarterStats 6.2.4100 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have ansmartertools · smarterstats | Kritik10,0 | — | %1,8 | 16 Ara 2011 |
40Planlayın | CVE-2021-32234İstismar yok | SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.smartertools · smartermail | Kritik9,8 | — | %2,2 | 17 Kas 2021 |
38İzleyin | CVE-2019-7213Kavram kanıtı | SmarterTools SmarterMail 16.x before build 6985 allows directory traversal.smartertools · smartermail · CWE-22 | Orta6,5 | — | %41,5 | 24 Nis 2019 |
34İzleyin | CVE-2026-7807İstismar yok | SmarterTools SmarterMail < Build 9560 Server Local File Inclusion via the /api/v1/report/summary/{type} APIsmartertools · smartermail · CWE-22 | Yüksek8,7 | — | %0,3 | 8 May 2026 |
32İzleyin | CVE-2004-2583İstismar yok | SMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service (CPU consumption) via a smartertools · smartermail | Yüksek7,8 | — | %1,8 | 31 Ara 2004 |
32İzleyin | CVE-2020-29548İstismar yok | An issue was discovered in SmarterTools SmarterMail through 100.0.7537.smartertools · smartermail · CWE-77 | Yüksek8,1 | — | %1,1 | 17 Ağu 2021 |
32İzleyin | CVE-2019-7212İstismar yok | SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys.smartertools · smartermail · CWE-798 | Yüksek8,2 | — | %1,0 | 24 Nis 2019 |
32İzleyin | CVE-2026-40514İstismar yok | SmarterTools SmarterMail < Build 9610 Cryptographic Weakness via Weak RNGsmartertools · smartermail · CWE-338 | Yüksek8,2 | — | %0,3 | 27 Nis 2026 |
31İzleyin | CVE-2011-2155İstismar yok | Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocsmartertools · smarterstats · CWE-287 | Yüksek7,5 | — | %3,9 | 20 May 2011 |
31İzleyin | CVE-2011-2149İstismar yok | Multiple SQL injection vulnerabilities in the SmarterTools SmarterStats 6.0 web server allow remote attackers to execute arbitrary SQL commasmartertools · smarterstats · CWE-89 | Yüksek7,5 | — | %2,4 | 20 May 2011 |
29İzleyin | CVE-2022-24387İstismar yok | File upload and overwrite to app_data/Config in SmarterTrack v100.0.8019.14010smartertools · smartertrack · CWE-434 | Yüksek7,2 | — | %2,1 | 14 Mar 2022 |
27İzleyin | CVE-2020-36926İstismar yok | SmarterTools SmarterTrack 7922 -Information Disclosuresmartertools · smartertrack · CWE-497 | Orta6,9 | — | %0,6 | 15 Oca 2026 |
27İzleyin | CVE-2026-25067İstismar yok | SmarterTools SmarterMail < Build 9518 Unauthenticated background-of-the-day Path Coercionsmartertools · smartermail · CWE-706 | Orta6,9 | — | %0,3 | 29 Oca 2026 |
26İzleyin | CVE-2022-24385İstismar yok | Information disclosure via direct object access on SmarterTrack v100.0.8019.14010smartertools · smartertrack · CWE-425 | Orta6,5 | — | %0,9 | 14 Mar 2022 |
25İzleyin | CVE-2022-24384Kavram kanıtı | Reflective XSS on SmarterTrack v100.0.8019.14010smartertools · smartertrack · CWE-79 | Orta6,1 | — | %4,1 | 14 Mar 2022 |
25İzleyin | CVE-2017-14620Kavram kanıtı | SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Ssmartertools · smarterstats · CWE-79 | Orta6,1 | — | %2,5 | 29 Eyl 2017 |
24İzleyin | CVE-2015-9276İstismar yok | SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms.smartertools · smartermail · CWE-79 | Orta6,1 | — | %1,1 | 16 Oca 2019 |
24İzleyin | CVE-2022-24386İstismar yok | Stored XSS in SmarterTrack v100.0.8019.14010smartertools · smartertrack · CWE-79 | Orta6,1 | — | %0,7 | 14 Mar 2022 |
- CVE-2026-2376096Hemen
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %97smartertools · smartermail22 Oca 2026
- CVE-2025-5269196Hemen
Upload Arbitrary Files
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %86smartertools · smartermail28 Ara 2025
- CVE-2026-2442393Hemen
SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %88smartertools · smartermail23 Oca 2026
- CVE-2019-721464Bu hafta
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data.
KritikCVSS 9,8SilahlaştırılmışEPSS %85smartertools · smartermail24 Nis 2019
- CVE-2011-214842Planlayın
Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involvi
KritikCVSS 10,0İstismar yokEPSS %5smartertools · smarterstats20 May 2011
- CVE-2011-215841Planlayın
The SmarterTools SmarterStats 6.0 web server sends incorrect Content-Type headers for certain resources, which might allow remote attackers
KritikCVSS 10,0İstismar yokEPSS %4smartertools · smarterstats20 May 2011
- CVE-2011-215941Planlayın
The SmarterTools SmarterStats 6.0 web server omits the Content-Type header for certain resources, which might allow remote attackers to have
KritikCVSS 10,0İstismar yokEPSS %4smartertools · smarterstats20 May 2011
- CVE-2011-475241Planlayın
SmarterTools SmarterStats 6.2.4100 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an
KritikCVSS 10,0İstismar yokEPSS %2smartertools · smarterstats16 Ara 2011
- CVE-2021-3223440Planlayın
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.
KritikCVSS 9,8İstismar yokEPSS %2smartertools · smartermail17 Kas 2021
- CVE-2019-721338İzleyin
SmarterTools SmarterMail 16.x before build 6985 allows directory traversal.
OrtaCVSS 6,5Kavram kanıtıEPSS %42smartertools · smartermail24 Nis 2019
- CVE-2026-780734İzleyin
SmarterTools SmarterMail < Build 9560 Server Local File Inclusion via the /api/v1/report/summary/{type} API
YüksekCVSS 8,7İstismar yokEPSS %0smartertools · smartermail8 May 2026
- CVE-2004-258332İzleyin
SMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service (CPU consumption) via a
YüksekCVSS 7,8İstismar yokEPSS %2smartertools · smartermail31 Ara 2004
- CVE-2020-2954832İzleyin
An issue was discovered in SmarterTools SmarterMail through 100.0.7537.
YüksekCVSS 8,1İstismar yokEPSS %1smartertools · smartermail17 Ağu 2021
- CVE-2019-721232İzleyin
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys.
YüksekCVSS 8,2İstismar yokEPSS %1smartertools · smartermail24 Nis 2019
- CVE-2026-4051432İzleyin
SmarterTools SmarterMail < Build 9610 Cryptographic Weakness via Weak RNG
YüksekCVSS 8,2İstismar yokEPSS %0smartertools · smartermail27 Nis 2026
- CVE-2011-215531İzleyin
Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autoc
YüksekCVSS 7,5İstismar yokEPSS %4smartertools · smarterstats20 May 2011
- CVE-2011-214931İzleyin
Multiple SQL injection vulnerabilities in the SmarterTools SmarterStats 6.0 web server allow remote attackers to execute arbitrary SQL comma
YüksekCVSS 7,5İstismar yokEPSS %2smartertools · smarterstats20 May 2011
- CVE-2022-2438729İzleyin
File upload and overwrite to app_data/Config in SmarterTrack v100.0.8019.14010
YüksekCVSS 7,2İstismar yokEPSS %2smartertools · smartertrack14 Mar 2022
- CVE-2020-3692627İzleyin
SmarterTools SmarterTrack 7922 -Information Disclosure
OrtaCVSS 6,9İstismar yokEPSS %1smartertools · smartertrack15 Oca 2026
- CVE-2026-2506727İzleyin
SmarterTools SmarterMail < Build 9518 Unauthenticated background-of-the-day Path Coercion
OrtaCVSS 6,9İstismar yokEPSS %0smartertools · smartermail29 Oca 2026
- CVE-2022-2438526İzleyin
Information disclosure via direct object access on SmarterTrack v100.0.8019.14010
OrtaCVSS 6,5İstismar yokEPSS %1smartertools · smartertrack14 Mar 2022
- CVE-2022-2438425İzleyin
Reflective XSS on SmarterTrack v100.0.8019.14010
OrtaCVSS 6,1Kavram kanıtıEPSS %4smartertools · smartertrack14 Mar 2022
- CVE-2017-1462025İzleyin
SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in S
OrtaCVSS 6,1Kavram kanıtıEPSS %2smartertools · smarterstats29 Eyl 2017
- CVE-2015-927624İzleyin
SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms.
OrtaCVSS 6,1İstismar yokEPSS %1smartertools · smartermail16 Oca 2019
- CVE-2022-2438624İzleyin
Stored XSS in SmarterTrack v100.0.8019.14010
OrtaCVSS 6,1İstismar yokEPSS %1smartertools · smartertrack14 Mar 2022