starfish kayıtları
starfish üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2001-1005İstismar yok | Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows astarfish · truesync desktop | Yüksek7,5 | — | %0,7 | 31 Ağu 2001 |
28İzleyin | CVE-2021-24753İstismar yok | Rich Reviews by Starfish < 1.9.6 - Admin+ SQL Injectionstarfish · rich review · CWE-89 | Yüksek7,2 | — | %1,5 | 27 Ara 2021 |
24İzleyin | CVE-2019-25216İstismar yok | Rich Reviews <= 1.7.4 - Stored Cross-Site Scriptingstarfish · rich review · CWE-79 | Orta6,1 | — | %0,5 | 16 Eki 2024 |
20İzleyin | CVE-2001-1006İstismar yok | Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to resstarfish · truesync desktop | Orta5,0 | — | %1,1 | 31 Ağu 2001 |
20İzleyin | CVE-2001-1007İstismar yok | Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrestarfish · truesync desktop | Orta5,0 | — | %1,1 | 31 Ağu 2001 |
17İzleyin | CVE-2021-36861İstismar yok | WordPress Rich Reviews by Starfish plugin <= 1.9.14 - Cross-Site Request Forgery (CSRF) vulnerabilitystarfish · rich review · CWE-352 | Orta4,3 | — | %0,3 | 5 Ağu 2022 |
- CVE-2001-100530İzleyin
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows a
YüksekCVSS 7,5İstismar yokEPSS %1starfish · truesync desktop31 Ağu 2001
- CVE-2021-2475328İzleyin
Rich Reviews by Starfish < 1.9.6 - Admin+ SQL Injection
YüksekCVSS 7,2İstismar yokEPSS %1starfish · rich review27 Ara 2021
- CVE-2019-2521624İzleyin
Rich Reviews <= 1.7.4 - Stored Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1starfish · rich review16 Eki 2024
- CVE-2001-100620İzleyin
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to res
OrtaCVSS 5,0İstismar yokEPSS %1starfish · truesync desktop31 Ağu 2001
- CVE-2001-100720İzleyin
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorre
OrtaCVSS 5,0İstismar yokEPSS %1starfish · truesync desktop31 Ağu 2001
- CVE-2021-3686117İzleyin
WordPress Rich Reviews by Starfish plugin <= 1.9.14 - Cross-Site Request Forgery (CSRF) vulnerability
OrtaCVSS 4,3İstismar yokEPSS %0starfish · rich review5 Ağu 2022