syspass kayıtları
syspass üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %14,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-326 Inadequate Encryption Strength1
- CWE-73 External Control of File Name or Path1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2025-25477İstismar yok | A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be syspass · syspass · CWE-74 | Yüksek8,1 | — | %0,4 | 27 Şub 2025 |
30İzleyin | CVE-2017-5999İstismar yok | An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers.syspass · syspass · CWE-326 | Yüksek7,5 | — | %1,1 | 6 Mar 2017 |
26İzleyin | CVE-2025-25478İstismar yok | The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames.syspass · syspass · CWE-73 | Orta6,5 | — | %0,4 | 28 Şub 2025 |
24İzleyin | CVE-2017-9306İstismar yok | inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" susyspass · syspass · CWE-79 | Orta6,1 | — | %0,9 | 31 May 2017 |
24İzleyin | CVE-2024-42904İstismar yok | A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a craftesyspass · syspass · CWE-79 | Orta6,1 | — | %0,3 | 3 Eyl 2024 |
21İzleyin | CVE-2022-4930İstismar yok | nuxsmin sysPass URL cross site scriptingsyspass · syspass · CWE-79 | Orta5,4 | — | %0,5 | 6 Mar 2023 |
21İzleyin | CVE-2025-25476İstismar yok | A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javsyspass · syspass · CWE-79 | Orta5,4 | — | %0,3 | 28 Şub 2025 |
- CVE-2025-2547732İzleyin
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be
YüksekCVSS 8,1İstismar yokEPSS %0syspass · syspass27 Şub 2025
- CVE-2017-599930İzleyin
An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers.
YüksekCVSS 7,5İstismar yokEPSS %1syspass · syspass6 Mar 2017
- CVE-2025-2547826İzleyin
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames.
OrtaCVSS 6,5İstismar yokEPSS %0syspass · syspass28 Şub 2025
- CVE-2017-930624İzleyin
inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" su
OrtaCVSS 6,1İstismar yokEPSS %1syspass · syspass31 May 2017
- CVE-2024-4290424İzleyin
A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafte
OrtaCVSS 6,1İstismar yokEPSS %0syspass · syspass3 Eyl 2024
- CVE-2022-493021İzleyin
nuxsmin sysPass URL cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1syspass · syspass6 Mar 2023
- CVE-2025-2547621İzleyin
A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Jav
OrtaCVSS 5,4İstismar yokEPSS %0syspass · syspass28 Şub 2025