stimulsoft kayıtları
stimulsoft üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %33,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-552 Files or Directories Accessible to External Parties1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2020-15865İstismar yok | A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-6stimulsoft · reports · CWE-94 | Kritik9,8 | — | %5,1 | 18 Ağu 2020 |
40Planlayın | CVE-2024-24398Kavram kanıtı | Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrarystimulsoft · dashboards.php · CWE-22 | Kritik9,8 | — | %2,0 | 5 Şub 2024 |
40Planlayın | CVE-2023-25261Kavram kanıtı | Certain Stimulsoft GmbH products are affected by: Remote Code Execution.stimulsoft · designer · CWE-94 | Kritik9,8 | — | %1,9 | 27 Mar 2023 |
39İzleyin | CVE-2021-42777İstismar yok | Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any macstimulsoft · reports · CWE-209 | Kritik9,8 | — | %1,0 | 29 Eki 2022 |
30İzleyin | CVE-2023-25262Kavram kanıtı | Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF).stimulsoft · designer · CWE-918 | Yüksek7,5 | — | %0,9 | 27 Mar 2023 |
30İzleyin | CVE-2023-25260Kavram kanıtı | Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.stimulsoft · designer · CWE-552 | Yüksek7,5 | — | %0,8 | 28 Mar 2023 |
24İzleyin | CVE-2024-24396Kavram kanıtı | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrarstimulsoft · dashboard.js · CWE-79 | Orta6,1 | — | %0,8 | 5 Şub 2024 |
22İzleyin | CVE-2023-25263Kavram kanıtı | In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decrystimulsoft · designer · CWE-312 | Orta5,5 | — | %0,2 | 27 Mar 2023 |
21İzleyin | CVE-2024-24397Kavram kanıtı | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrarstimulsoft · dashboards.js · CWE-79 | Orta5,4 | — | %0,8 | 5 Şub 2024 |
- CVE-2020-1586541Planlayın
A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-6
KritikCVSS 9,8İstismar yokEPSS %5stimulsoft · reports18 Ağu 2020
- CVE-2024-2439840Planlayın
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary
KritikCVSS 9,8Kavram kanıtıEPSS %2stimulsoft · dashboards.php5 Şub 2024
- CVE-2023-2526140Planlayın
Certain Stimulsoft GmbH products are affected by: Remote Code Execution.
KritikCVSS 9,8Kavram kanıtıEPSS %2stimulsoft · designer27 Mar 2023
- CVE-2021-4277739İzleyin
Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any mac
KritikCVSS 9,8İstismar yokEPSS %1stimulsoft · reports29 Eki 2022
- CVE-2023-2526230İzleyin
Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF).
YüksekCVSS 7,5Kavram kanıtıEPSS %1stimulsoft · designer27 Mar 2023
- CVE-2023-2526030İzleyin
Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.
YüksekCVSS 7,5Kavram kanıtıEPSS %1stimulsoft · designer28 Mar 2023
- CVE-2024-2439624İzleyin
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrar
OrtaCVSS 6,1Kavram kanıtıEPSS %1stimulsoft · dashboard.js5 Şub 2024
- CVE-2023-2526322İzleyin
In Stimulsoft Designer (Desktop) 2023.1.5, and 2023.1.4, once an attacker decompiles the Stimulsoft.report.dll the attacker is able to decry
OrtaCVSS 5,5Kavram kanıtıEPSS %0stimulsoft · designer27 Mar 2023
- CVE-2024-2439721İzleyin
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrar
OrtaCVSS 5,4Kavram kanıtıEPSS %1stimulsoft · dashboards.js5 Şub 2024