SupportCandy kayıtları
supportcandy üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2023-1730Kavram kanıtı | SupportCandy < 3.1.5 - Unauthenticated SQLisupportcandy · supportcandy · CWE-89 | Kritik9,8 | — | %40,6 | 2 May 2023 |
42Planlayın | CVE-2019-11223Kavram kanıtı | An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrarsupportcandy · supportcandy · CWE-434 | Kritik9,8 | — | %8,8 | 18 Nis 2019 |
35İzleyin | CVE-2023-2719İstismar yok | SupportCandy < 3.1.7 - Subscriber+ SQLisupportcandy · supportcandy · CWE-89 | Yüksek8,8 | — | %1,2 | 19 Haz 2023 |
35İzleyin | CVE-2021-24879İstismar yok | SupportCandy < 2.2.7 - CSRF to Cross-Site Scriptingsupportcandy · supportcandy · CWE-352 | Yüksek8,8 | — | %0,6 | 7 Şub 2022 |
30İzleyin | CVE-2021-24839İstismar yok | SupportCandy < 2.2.5 - Unauthenticated Arbitrary Ticket Deletionsupportcandy · supportcandy · CWE-862 | Yüksek7,5 | — | %1,2 | 7 Şub 2022 |
28İzleyin | CVE-2023-2805İstismar yok | SupportCandy < 3.1.7 - Admin+ SQLisupportcandy · supportcandy · CWE-89 | Yüksek7,2 | — | %0,9 | 19 Haz 2023 |
26İzleyin | CVE-2021-24843İstismar yok | SupportCandy < 2.2.7 - Arbitrary Ticket Deletion via CSRFsupportcandy · supportcandy · CWE-352 | Orta6,5 | — | %0,5 | 7 Şub 2022 |
24İzleyin | CVE-2021-24878Kavram kanıtı | SupportCandy < 2.2.7 - Reflected Cross-Site Scriptingsupportcandy · supportcandy · CWE-79 | Orta6,1 | — | %1,2 | 7 Şub 2022 |
21İzleyin | CVE-2021-24880İstismar yok | SupportCandy < 2.2.7 - Contributor+ Stored Cross-Site Scriptingsupportcandy · supportcandy · CWE-79 | Orta5,4 | — | %0,6 | 7 Şub 2022 |
- CVE-2023-173051Planlayın
SupportCandy < 3.1.5 - Unauthenticated SQLi
KritikCVSS 9,8Kavram kanıtıEPSS %41supportcandy · supportcandy2 May 2023
- CVE-2019-1122342Planlayın
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrar
KritikCVSS 9,8Kavram kanıtıEPSS %9supportcandy · supportcandy18 Nis 2019
- CVE-2023-271935İzleyin
SupportCandy < 3.1.7 - Subscriber+ SQLi
YüksekCVSS 8,8İstismar yokEPSS %1supportcandy · supportcandy19 Haz 2023
- CVE-2021-2487935İzleyin
SupportCandy < 2.2.7 - CSRF to Cross-Site Scripting
YüksekCVSS 8,8İstismar yokEPSS %1supportcandy · supportcandy7 Şub 2022
- CVE-2021-2483930İzleyin
SupportCandy < 2.2.5 - Unauthenticated Arbitrary Ticket Deletion
YüksekCVSS 7,5İstismar yokEPSS %1supportcandy · supportcandy7 Şub 2022
- CVE-2023-280528İzleyin
SupportCandy < 3.1.7 - Admin+ SQLi
YüksekCVSS 7,2İstismar yokEPSS %1supportcandy · supportcandy19 Haz 2023
- CVE-2021-2484326İzleyin
SupportCandy < 2.2.7 - Arbitrary Ticket Deletion via CSRF
OrtaCVSS 6,5İstismar yokEPSS %1supportcandy · supportcandy7 Şub 2022
- CVE-2021-2487824İzleyin
SupportCandy < 2.2.7 - Reflected Cross-Site Scripting
OrtaCVSS 6,1Kavram kanıtıEPSS %1supportcandy · supportcandy7 Şub 2022
- CVE-2021-2488021İzleyin
SupportCandy < 2.2.7 - Contributor+ Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %1supportcandy · supportcandy7 Şub 2022