status kayıtları
status üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-306 Missing Authentication for Critical Function1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-12164İstismar yok | ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.status · react native desktop | Kritik9,8 | — | %4,1 | 23 Tem 2019 |
39İzleyin | CVE-2010-4660İstismar yok | Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..status · statusnet · CWE-20 | Kritik9,8 | — | %1,3 | 20 Kas 2019 |
30İzleyin | CVE-2013-4137İstismar yok | Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via status · statusnet · CWE-89 | Yüksek7,5 | — | %1,1 | 11 Eki 2013 |
24İzleyin | CVE-2011-3370İstismar yok | statusnet before 0.9.9 has XSSstatus · statusnet · CWE-79 | Orta6,1 | — | %1,0 | 12 Kas 2019 |
24İzleyin | CVE-2010-4659İstismar yok | Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.status · statusnet · CWE-79 | Orta6,1 | — | %0,9 | 20 Kas 2019 |
22İzleyin | CVE-2023-25780İstismar yok | Status Internet Co.,Ltd. PowerBPM - Broken Access Controlstatus · powerbpm · CWE-306 | Orta5,7 | — | %0,3 | 2 Haz 2023 |
21İzleyin | CVE-2010-4658İstismar yok | statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.status · statusnet · CWE-74 | Orta5,3 | — | %0,9 | 7 Şub 2020 |
20İzleyin | CVE-2011-3802İstismar yok | StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation status · statusnet · CWE-200 | Orta5,0 | — | %1,2 | 23 Eyl 2011 |
- CVE-2019-1216440Planlayın
ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.
KritikCVSS 9,8İstismar yokEPSS %4status · react native desktop23 Tem 2019
- CVE-2010-466039İzleyin
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
KritikCVSS 9,8İstismar yokEPSS %1status · statusnet20 Kas 2019
- CVE-2013-413730İzleyin
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via
YüksekCVSS 7,5İstismar yokEPSS %1status · statusnet11 Eki 2013
- CVE-2011-337024İzleyin
statusnet before 0.9.9 has XSS
OrtaCVSS 6,1İstismar yokEPSS %1status · statusnet12 Kas 2019
- CVE-2010-465924İzleyin
Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
OrtaCVSS 6,1İstismar yokEPSS %1status · statusnet20 Kas 2019
- CVE-2023-2578022İzleyin
Status Internet Co.,Ltd. PowerBPM - Broken Access Control
OrtaCVSS 5,7İstismar yokEPSS %0status · powerbpm2 Haz 2023
- CVE-2010-465821İzleyin
statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
OrtaCVSS 5,3İstismar yokEPSS %1status · statusnet7 Şub 2020
- CVE-2011-380220İzleyin
StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
OrtaCVSS 5,0İstismar yokEPSS %1status · statusnet23 Eyl 2011