İçeriğe atla
Noroxi

thingsboard kayıtları

thingsboard üreticisine ait 15 yayımlanmış kayıt.

Tüm kayıtlar

15 kayıt
  • CVE-2022-40004
    38İzleyin

    Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Lo

    KritikCVSS 9,6İstismar yokEPSS %1

    thingsboard · thingsboard15 Ara 2022

  • CVE-2020-27687
    35İzleyin

    ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails.

    YüksekCVSS 8,8İstismar yokEPSS %2

    thingsboard · thingsboard18 Ara 2020

  • CVE-2022-48341
    35İzleyin

    ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation.

    YüksekCVSS 8,8İstismar yokEPSS %1

    thingsboard · thingsboard23 Şub 2023

  • CVE-2022-45608
    35İzleyin

    An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and

    YüksekCVSS 8,8İstismar yokEPSS %1

    thingsboard · thingsboard1 Mar 2023

  • CVE-2023-45303
    35İzleyin

    ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker sup

    YüksekCVSS 8,8İstismar yokEPSS %1

    thingsboard · thingsboard6 Eki 2023

  • CVE-2023-26462
    32İzleyin

    ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege esc

    YüksekCVSS 8,1İstismar yokEPSS %1

    thingsboard · thingsboard23 Şub 2023

  • CVE-2025-34282
    28İzleyin

    ThingsBoard < v4.2.1 SVG Image SSRF

    OrtaCVSS 6,9Kavram kanıtıEPSS %2

    thingsboard · thingsboard17 Eki 2025

  • CVE-2024-3270
    26İzleyin

    ThingsBoard AdvancedFeature access control

    OrtaCVSS 6,5İstismar yokEPSS %1

    thingsboard · thingsboard3 Nis 2024

  • CVE-2024-55466
    26İzleyin

    An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1

    OrtaCVSS 6,5Kavram kanıtıEPSS %0

    thingsboard · thingsboard12 May 2025

  • CVE-2024-9358
    24İzleyin

    ThingsBoard HTTP RPC API resource consumption

    OrtaCVSS 6,0İstismar yokEPSS %1

    thingsboard · thingsboard30 Eyl 2024

  • CVE-2025-34281
    24İzleyin

    Stored Cross-Site Scripting (XSS) in ThingsBoard

    OrtaCVSS 6,2İstismar yokEPSS %0

    thingsboard · thingsboard17 Eki 2025

  • CVE-2022-31861
    21İzleyin

    Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.

    OrtaCVSS 5,4İstismar yokEPSS %1

    thingsboard · thingsboard13 Eyl 2022

  • CVE-2021-42750
    20İzleyin

    A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec

    OrtaCVSS 4,8Kavram kanıtıEPSS %3

    thingsboard · thingsboard12 Ağu 2022

  • CVE-2021-42751
    20İzleyin

    A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to injec

    OrtaCVSS 4,8Kavram kanıtıEPSS %3

    thingsboard · thingsboard12 Ağu 2022

  • CVE-2025-9094
    8İzleyin

    ThingsBoard Add Gateway special elements used in a template engine

    DüşükCVSS 2,1İstismar yokEPSS %0

    thingsboard · thingsboard17 Ağu 2025