thm kayıtları
thm üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %57,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-613 Insufficient Session Expiration1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2023-47107İstismar yok | PILOS account takeover through password reset poisoningthm · pilos · CWE-20 | Yüksek8,8 | — | %0,6 | 8 Kas 2023 |
25İzleyin | CVE-2025-62523İstismar yok | PILOS Misconfigured the Access-Control-Allow-Origin Headerthm · pilos · CWE-942 | Orta6,3 | — | %0,2 | 27 Eki 2025 |
22İzleyin | CVE-2023-37468İstismar yok | Storing unencrypted LDAP passwords in feedbacksystemthm · feedbacksystem · CWE-312 | Orta5,5 | — | %0,2 | 13 Tem 2023 |
21İzleyin | CVE-2025-62524İstismar yok | PILOS Exposes PHP versionthm · pilos · CWE-200 | Orta5,3 | — | %0,3 | 27 Eki 2025 |
20İzleyin | CVE-2025-62781İstismar yok | PILOS is missing session regeneration after password changethm · pilos · CWE-613 | Orta5,0 | — | %0,2 | 27 Eki 2025 |
18İzleyin | CVE-2026-22800İstismar yok | PILOS affected by a CSRF via GET request allows unintentional termination of all active video conferencesthm · pilos · CWE-352 | Orta4,5 | — | %0,1 | 12 Oca 2026 |
17İzleyin | CVE-2023-27485İstismar yok | Insufficient verification of authorisation when accessing subresults in thmmniii/fbs-corethm · feedbacksystem · CWE-863 | Orta4,3 | — | %0,5 | 7 Mar 2023 |
- CVE-2023-4710735İzleyin
PILOS account takeover through password reset poisoning
YüksekCVSS 8,8İstismar yokEPSS %1thm · pilos8 Kas 2023
- CVE-2025-6252325İzleyin
PILOS Misconfigured the Access-Control-Allow-Origin Header
OrtaCVSS 6,3İstismar yokEPSS %0thm · pilos27 Eki 2025
- CVE-2023-3746822İzleyin
Storing unencrypted LDAP passwords in feedbacksystem
OrtaCVSS 5,5İstismar yokEPSS %0thm · feedbacksystem13 Tem 2023
- CVE-2025-6252421İzleyin
PILOS Exposes PHP version
OrtaCVSS 5,3İstismar yokEPSS %0thm · pilos27 Eki 2025
- CVE-2025-6278120İzleyin
PILOS is missing session regeneration after password change
OrtaCVSS 5,0İstismar yokEPSS %0thm · pilos27 Eki 2025
- CVE-2026-2280018İzleyin
PILOS affected by a CSRF via GET request allows unintentional termination of all active video conferences
OrtaCVSS 4,5İstismar yokEPSS %0thm · pilos12 Oca 2026
- CVE-2023-2748517İzleyin
Insufficient verification of authorisation when accessing subresults in thmmniii/fbs-core
OrtaCVSS 4,3İstismar yokEPSS %1thm · feedbacksystem7 Mar 2023