thingsboard kayıtları
thingsboard üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %26,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-269 Improper Privilege Management2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-791 Incomplete Filtering of Special Elements1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2022-40004İstismar yok | Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Lothingsboard · thingsboard · CWE-79 | Kritik9,6 | — | %0,9 | 15 Ara 2022 |
35İzleyin | CVE-2020-27687İstismar yok | ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails.thingsboard · thingsboard · CWE-20 | Yüksek8,8 | — | %1,5 | 18 Ara 2020 |
35İzleyin | CVE-2022-48341İstismar yok | ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation.thingsboard · thingsboard · CWE-269 | Yüksek8,8 | — | %1,0 | 23 Şub 2023 |
35İzleyin | CVE-2022-45608İstismar yok | An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and thingsboard · thingsboard · CWE-269 | Yüksek8,8 | — | %0,9 | 1 Mar 2023 |
35İzleyin | CVE-2023-45303İstismar yok | ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supthingsboard · thingsboard · CWE-74 | Yüksek8,8 | — | %0,9 | 6 Eki 2023 |
32İzleyin | CVE-2023-26462İstismar yok | ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escthingsboard · thingsboard · CWE-798 | Yüksek8,1 | — | %1,1 | 23 Şub 2023 |
28İzleyin | CVE-2025-34282Kavram kanıtı | ThingsBoard < v4.2.1 SVG Image SSRFthingsboard · thingsboard · CWE-918 | Orta6,9 | — | %1,8 | 17 Eki 2025 |
26İzleyin | CVE-2024-3270İstismar yok | ThingsBoard AdvancedFeature access controlthingsboard · thingsboard · CWE-284 | Orta6,5 | — | %0,6 | 3 Nis 2024 |
26İzleyin | CVE-2024-55466Kavram kanıtı | An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 thingsboard · thingsboard · CWE-77 | Orta6,5 | — | %0,4 | 12 May 2025 |
24İzleyin | CVE-2024-9358İstismar yok | ThingsBoard HTTP RPC API resource consumptionthingsboard · thingsboard · CWE-400 | Orta6,0 | — | %0,8 | 30 Eyl 2024 |
24İzleyin | CVE-2025-34281İstismar yok | Stored Cross-Site Scripting (XSS) in ThingsBoardthingsboard · thingsboard · CWE-79 | Orta6,2 | — | %0,4 | 17 Eki 2025 |
21İzleyin | CVE-2022-31861İstismar yok | Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.thingsboard · thingsboard · CWE-79 | Orta5,4 | — | %0,6 | 13 Eyl 2022 |
20İzleyin | CVE-2021-42750Kavram kanıtı | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injecthingsboard · thingsboard · CWE-79 | Orta4,8 | — | %3,1 | 12 Ağu 2022 |
20İzleyin | CVE-2021-42751Kavram kanıtı | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injecthingsboard · thingsboard · CWE-79 | Orta4,8 | — | %3,1 | 12 Ağu 2022 |
8İzleyin | CVE-2025-9094İstismar yok | ThingsBoard Add Gateway special elements used in a template enginethingsboard · thingsboard · CWE-791 | Düşük2,1 | — | %0,3 | 17 Ağu 2025 |
- CVE-2022-4000438İzleyin
Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Lo
KritikCVSS 9,6İstismar yokEPSS %1thingsboard · thingsboard15 Ara 2022
- CVE-2020-2768735İzleyin
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails.
YüksekCVSS 8,8İstismar yokEPSS %2thingsboard · thingsboard18 Ara 2020
- CVE-2022-4834135İzleyin
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation.
YüksekCVSS 8,8İstismar yokEPSS %1thingsboard · thingsboard23 Şub 2023
- CVE-2022-4560835İzleyin
An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and
YüksekCVSS 8,8İstismar yokEPSS %1thingsboard · thingsboard1 Mar 2023
- CVE-2023-4530335İzleyin
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker sup
YüksekCVSS 8,8İstismar yokEPSS %1thingsboard · thingsboard6 Eki 2023
- CVE-2023-2646232İzleyin
ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege esc
YüksekCVSS 8,1İstismar yokEPSS %1thingsboard · thingsboard23 Şub 2023
- CVE-2025-3428228İzleyin
ThingsBoard < v4.2.1 SVG Image SSRF
OrtaCVSS 6,9Kavram kanıtıEPSS %2thingsboard · thingsboard17 Eki 2025
- CVE-2024-327026İzleyin
ThingsBoard AdvancedFeature access control
OrtaCVSS 6,5İstismar yokEPSS %1thingsboard · thingsboard3 Nis 2024
- CVE-2024-5546626İzleyin
An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1
OrtaCVSS 6,5Kavram kanıtıEPSS %0thingsboard · thingsboard12 May 2025
- CVE-2024-935824İzleyin
ThingsBoard HTTP RPC API resource consumption
OrtaCVSS 6,0İstismar yokEPSS %1thingsboard · thingsboard30 Eyl 2024
- CVE-2025-3428124İzleyin
Stored Cross-Site Scripting (XSS) in ThingsBoard
OrtaCVSS 6,2İstismar yokEPSS %0thingsboard · thingsboard17 Eki 2025
- CVE-2022-3186121İzleyin
Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.
OrtaCVSS 5,4İstismar yokEPSS %1thingsboard · thingsboard13 Eyl 2022
- CVE-2021-4275020İzleyin
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec
OrtaCVSS 4,8Kavram kanıtıEPSS %3thingsboard · thingsboard12 Ağu 2022
- CVE-2021-4275120İzleyin
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec
OrtaCVSS 4,8Kavram kanıtıEPSS %3thingsboard · thingsboard12 Ağu 2022
- CVE-2025-90948İzleyin
ThingsBoard Add Gateway special elements used in a template engine
DüşükCVSS 2,1İstismar yokEPSS %0thingsboard · thingsboard17 Ağu 2025