proges 漏洞与 CVE 列表(7)

产品(CPE): — CVE 数: 7

proges 漏洞概览

汇总 proges 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。

常见弱点模式包括 跨站脚本、CSRF、缓冲区溢出与内存损坏,在 生产负载与软件部署 使用场景中可能带来 应用崩溃、内存损坏与会话劫持 等风险。

相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。

漏洞分布趋势(近 24 个月)

显示 177 CVE 数
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
CVE 摘要 来源 最高 CVSS EPSS % 公开时间 更新时间
CVE-2024-3083 A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting a malicious web page. [email protected] 8.3 0.21% 2024-07-31 2026-06-17
CVE-2024-3082 A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other layers (e.g., full-disk encryption) have been enabled. [email protected] 4.2 0.07% 2024-07-31 2026-06-17
CVE-2024-31203 A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition on the target component. [email protected] 3.3 0.05% 2024-07-31 2026-06-17
CVE-2024-31202 A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation. [email protected] 7.8 0.16% 2024-07-31 2026-06-17
CVE-2024-31201 A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on the local machine. [email protected] 6.5 0.16% 2024-07-31 2026-06-17
CVE-2024-31200 A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser. [email protected] 4.2 0.19% 2024-07-31 2026-06-17
CVE-2024-31199 A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code. [email protected] 8.8 0.30% 2024-07-31 2026-06-17
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
cvelogic Threat Intelligence