This page aggregates publicly disclosed CVE and security risk information related to b1ackc4t, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2024-37770 | 14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload. | [email protected] | 9.1 | 1.57% | 2024-07-10 | 2026-06-17 |
| CVE-2024-37767 | Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request. | [email protected] | 7.5 | 0.40% | 2024-07-05 | 2026-06-17 |
| CVE-2024-37769 | Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request. | [email protected] | 8.8 | 0.46% | 2024-07-05 | 2026-06-17 |
| CVE-2024-37768 | 14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id. | [email protected] | 9.1 | 0.57% | 2024-07-05 | 2026-06-17 |