Priority
by Priority
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23460 | Cri | 0.59 | 9.1 | 0.01 | Feb 15, 2023 | Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass. | ||
| CVE-2023-23459 | Cri | 0.59 | 9.1 | 0.01 | Feb 15, 2023 | Priority Windows may allow Command Execution via SQL Injection using an unspecified method. | ||
| CVE-2024-41697 | Med | 0.40 | 6.1 | 0.00 | Aug 20, 2024 | Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | ||
| CVE-2022-23173 | Med | 0.36 | 5.5 | 0.01 | Jul 6, 2022 | this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - demo site" then he can see in this menu all the functionality of the application. If the attacker will try to click on one of the… | ||
| CVE-2022-23172 | Med | 0.36 | 5.5 | 0.00 | Jul 6, 2022 | An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the system and which are not. | ||
| CVE-2024-41699 | Med | 0.29 | 4.4 | 0.00 | Aug 20, 2024 | Priority – CWE-552: Files or Directories Accessible to External Parties | ||
| CVE-2024-41698 | Med | 0.28 | 4.3 | 0.00 | Aug 20, 2024 | Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
- risk 0.59cvss 9.1epss 0.01
Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.
- risk 0.59cvss 9.1epss 0.01
Priority Windows may allow Command Execution via SQL Injection using an unspecified method.
- risk 0.40cvss 6.1epss 0.00
Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
- risk 0.36cvss 5.5epss 0.01
this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - demo site" then he can see in this menu all the functionality of the application. If the attacker will try to click on one of the…
- risk 0.36cvss 5.5epss 0.00
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the system and which are not.
- risk 0.29cvss 4.4epss 0.00
Priority – CWE-552: Files or Directories Accessible to External Parties
- risk 0.28cvss 4.3epss 0.00
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor