İçeriğe atla
Noroxi

spiceworks kayıtları

spiceworks üreticisine ait 9 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

9 kayıt
  • CVE-2017-7237
    41Planlayın

    The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configuratio

    KritikCVSS 9,8Kavram kanıtıEPSS %7

    spiceworks · spiceworks6 Nis 2017

  • CVE-2021-43609
    36İzleyin

    An issue was discovered in Spiceworks Help Desk Server before 1.3.3.

    YüksekCVSS 8,8Kavram kanıtıEPSS %2

    spiceworks · help desk server8 Kas 2023

  • CVE-2020-23451
    35İzleyin

    Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.

    YüksekCVSS 8,8İstismar yokEPSS %1

    spiceworks · spiceworks15 Eyl 2020

  • CVE-2020-25901
    26İzleyin

    Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned

    OrtaCVSS 6,1Kavram kanıtıEPSS %5

    spiceworks · spiceworks18 Ara 2020

  • CVE-2012-2956
    26İzleyin

    SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter

    OrtaCVSS 6,5Kavram kanıtıEPSS %1

    spiceworks · spiceworks17 Eyl 2014

  • CVE-2015-6021
    24İzleyin

    Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.

    OrtaCVSS 6,1İstismar yokEPSS %1

    spiceworks · desktop9 Nis 2017

  • CVE-2020-23450
    21İzleyin

    Spiceworks Version <= 7.5.00107 is affected by XSS.

    OrtaCVSS 5,4İstismar yokEPSS %1

    spiceworks · spiceworks1 Eyl 2020

  • CVE-2012-6658
    18İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML vi

    OrtaCVSS 4,3Kavram kanıtıEPSS %2

    spiceworks · spiceworks17 Eyl 2014

  • CVE-2014-3740
    15İzleyin

    Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or

    DüşükCVSS 3,5Kavram kanıtıEPSS %3

    spiceworks · spiceworks11 Eyl 2014