Zend kayıtları
zend üreticisine ait 46 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %56,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-20 Improper Input Validation2
- CWE-287 Improper Authentication2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
46 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2021-3007Kavram kanıtı | Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execuzend · zend framework · CWE-502 | Kritik9,8 | — | %75,3 | 3 Oca 2021 |
51Planlayın | CVE-2012-3363Kavram kanıtı | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows rezend · zend framework · CWE-611 | Kritik9,1 | — | %50,2 | 13 Şub 2013 |
51Planlayın | CVE-2016-10034Kavram kanıtı | The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framewzend · zend framework · CWE-77 | Kritik9,8 | — | %38,4 | 30 Ara 2016 |
40Planlayın | CVE-2016-4861Kavram kanıtı | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injeczend · zend framework · CWE-89 | Kritik9,8 | — | %4,1 | 16 Şub 2017 |
40Planlayın | CVE-2011-1939Kavram kanıtı | SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conzend · zend framework · CWE-89 | Kritik9,8 | — | %3,9 | 26 Kas 2019 |
40Planlayın | CVE-2015-7695İstismar yok | The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrzend · zend framework · CWE-89 | Kritik9,8 | — | %3,0 | 7 Haz 2016 |
40Planlayın | CVE-2014-8089İstismar yok | SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extensionzend · zend framework · CWE-89 | Kritik9,8 | — | %2,6 | 17 Şub 2020 |
40Planlayın | CVE-2014-4914İstismar yok | The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to cozend · zend framework · CWE-89 | Kritik9,8 | — | %2,3 | 29 Ara 2017 |
40Planlayın | CVE-2016-6233İstismar yok | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injeczend · zend framework · CWE-89 | Kritik9,8 | — | %2,0 | 16 Şub 2017 |
39İzleyin | CVE-2020-8986İstismar yok | lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attazend · zendto · CWE-754 | Kritik9,8 | — | %1,5 | 24 Mar 2020 |
39İzleyin | CVE-2020-29312İstismar yok | An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function.zend · zend framework · CWE-502 | Kritik9,8 | — | %1,3 | 4 Nis 2023 |
39İzleyin | CVE-2015-0270İstismar yok | Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.zend · framework · CWE-89 | Kritik9,8 | — | %1,1 | 25 Eki 2019 |
37İzleyin | CVE-2024-9129İstismar yok | Format String Injection in Zend Serverzend · zend server · CWE-134 | Kritik9,3 | — | %0,4 | 22 Eki 2024 |
36İzleyin | CVE-2015-1555İstismar yok | Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions withouzend · zend framework · CWE-20 | Kritik9,1 | — | %1,4 | 7 Ağu 2017 |
35İzleyin | CVE-2015-1786İstismar yok | Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token idenzend · zend framework · CWE-352 | Yüksek8,8 | — | %0,7 | 8 Haz 2017 |
35İzleyin | CVE-2020-8985İstismar yok | ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.zend · zendto · CWE-79 | Yüksek8,8 | — | %0,5 | 24 Mar 2020 |
31İzleyin | CVE-2006-4431İstismar yok | Multiple buffer overflows in the (a) Session Clustering Daemon and the (b) mod_cluster module in the Zend Platform 2.2.1 and earlier allow rzend · zend platform · CWE-119 | Yüksek7,5 | — | %4,6 | 28 Ağu 2006 |
31İzleyin | CVE-2014-2685İstismar yok | The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 beforezend · zend framework · CWE-287 | Yüksek7,5 | — | %2,8 | 4 Eyl 2014 |
31İzleyin | CVE-2006-4432İstismar yok | Directory traversal vulnerability in Zend Platform 2.2.1 and earlier allows remote attackers to overwrite arbitrary files via a ..zend · zend platform | Yüksek7,5 | — | %2,1 | 28 Ağu 2006 |
31İzleyin | CVE-2015-5723İstismar yok | Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 ozend · zend-cache · CWE-264 | Yüksek7,8 | — | %0,4 | 7 Haz 2016 |
30İzleyin | CVE-2015-5161Kavram kanıtı | The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when runninzend · zend framework | Orta6,8 | — | %9,9 | 25 Ağu 2015 |
30İzleyin | CVE-2015-7503İstismar yok | Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSAzend · zend framework · CWE-320 | Yüksek7,5 | — | %1,4 | 10 Eki 2017 |
30İzleyin | CVE-2020-8984İstismar yok | lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.zend · zendto · CWE-346 | Yüksek7,5 | — | %0,5 | 24 Mar 2020 |
28İzleyin | CVE-2014-2682İstismar yok | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobblerzend · zendrest · CWE-19 | Orta6,8 | — | %2,2 | 15 Kas 2014 |
27İzleyin | CVE-2006-5900İstismar yok | Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview zend · zend framework preview | Orta6,8 | — | %1,2 | 15 Kas 2006 |
- CVE-2021-300762Bu hafta
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execu
KritikCVSS 9,8Kavram kanıtıEPSS %75zend · zend framework3 Oca 2021
- CVE-2012-336351Planlayın
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows re
KritikCVSS 9,1Kavram kanıtıEPSS %50zend · zend framework13 Şub 2013
- CVE-2016-1003451Planlayın
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framew
KritikCVSS 9,8Kavram kanıtıEPSS %38zend · zend framework30 Ara 2016
- CVE-2016-486140Planlayın
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injec
KritikCVSS 9,8Kavram kanıtıEPSS %4zend · zend framework16 Şub 2017
- CVE-2011-193940Planlayın
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in con
KritikCVSS 9,8Kavram kanıtıEPSS %4zend · zend framework26 Kas 2019
- CVE-2015-769540Planlayın
The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitr
KritikCVSS 9,8İstismar yokEPSS %3zend · zend framework7 Haz 2016
- CVE-2014-808940Planlayın
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension
KritikCVSS 9,8İstismar yokEPSS %3zend · zend framework17 Şub 2020
- CVE-2014-491440Planlayın
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to co
KritikCVSS 9,8İstismar yokEPSS %2zend · zend framework29 Ara 2017
- CVE-2016-623340Planlayın
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injec
KritikCVSS 9,8İstismar yokEPSS %2zend · zend framework16 Şub 2017
- CVE-2020-898639İzleyin
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an atta
KritikCVSS 9,8İstismar yokEPSS %2zend · zendto24 Mar 2020
- CVE-2020-2931239İzleyin
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function.
KritikCVSS 9,8İstismar yokEPSS %1zend · zend framework4 Nis 2023
- CVE-2015-027039İzleyin
Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.
KritikCVSS 9,8İstismar yokEPSS %1zend · framework25 Eki 2019
- CVE-2024-912937İzleyin
Format String Injection in Zend Server
KritikCVSS 9,3İstismar yokEPSS %0zend · zend server22 Eki 2024
- CVE-2015-155536İzleyin
Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions withou
KritikCVSS 9,1İstismar yokEPSS %1zend · zend framework7 Ağu 2017
- CVE-2015-178635İzleyin
Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token iden
YüksekCVSS 8,8İstismar yokEPSS %1zend · zend framework8 Haz 2017
- CVE-2020-898535İzleyin
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
YüksekCVSS 8,8İstismar yokEPSS %1zend · zendto24 Mar 2020
- CVE-2006-443131İzleyin
Multiple buffer overflows in the (a) Session Clustering Daemon and the (b) mod_cluster module in the Zend Platform 2.2.1 and earlier allow r
YüksekCVSS 7,5İstismar yokEPSS %5zend · zend platform28 Ağu 2006
- CVE-2014-268531İzleyin
The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before
YüksekCVSS 7,5İstismar yokEPSS %3zend · zend framework4 Eyl 2014
- CVE-2006-443231İzleyin
Directory traversal vulnerability in Zend Platform 2.2.1 and earlier allows remote attackers to overwrite arbitrary files via a ..
YüksekCVSS 7,5İstismar yokEPSS %2zend · zend platform28 Ağu 2006
- CVE-2015-572331İzleyin
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 o
YüksekCVSS 7,8İstismar yokEPSS %0zend · zend-cache7 Haz 2016
- CVE-2015-516130İzleyin
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when runnin
OrtaCVSS 6,8Kavram kanıtıEPSS %10zend · zend framework25 Ağu 2015
- CVE-2015-750330İzleyin
Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA
YüksekCVSS 7,5İstismar yokEPSS %1zend · zend framework10 Eki 2017
- CVE-2020-898430İzleyin
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
YüksekCVSS 7,5İstismar yokEPSS %0zend · zendto24 Mar 2020
- CVE-2014-268228İzleyin
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler
OrtaCVSS 6,8İstismar yokEPSS %2zend · zendrest15 Kas 2014
- CVE-2006-590027İzleyin
Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview
OrtaCVSS 6,8İstismar yokEPSS %1zend · zend framework preview15 Kas 2006