derbynet CVE 脆弱性と CVE 一覧(11)

製品(CPE): — CVE 件数: 11

derbynet 脆弱性概要

derbynet 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

過去の問題は主に vendor risk cross-site scripting and vendor risk sql injection などに関し、一部は vendor impact session compromise を招き、vendor surface software deployment and vendor surface production workloads 関連の場面に影響します。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 111 / 11 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2024-30929 Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlist.php [email protected] 8.0 0.53% 2024-04-18 2025-11-04
CVE-2024-30928 SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/query.slide.next.inc [email protected] 8.1 0.18% 2024-04-18 2025-11-04
CVE-2024-30927 Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component. [email protected] 6.3 0.26% 2024-04-18 2025-11-04
CVE-2024-30926 Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component. [email protected] 4.6 0.43% 2024-04-18 2025-11-04
CVE-2024-30925 Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component. [email protected] 6.5 0.26% 2024-04-18 2025-11-04
CVE-2024-30924 Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component. [email protected] 4.6 0.19% 2024-04-18 2025-11-04
CVE-2024-30923 SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering [email protected] 9.8 4.93% 2024-04-18 2025-11-04
CVE-2024-30922 SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendering. [email protected] 9.8 4.93% 2024-04-18 2025-11-04
CVE-2024-30921 Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component. [email protected] 5.4 1.12% 2024-04-18 2025-11-04
CVE-2024-30920 Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php component. [email protected] 7.4 0.90% 2024-04-18 2025-11-04
CVE-2024-31818 Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php component. [email protected] 9.8 12.09% 2024-04-12 2025-06-17
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence