Derbynet
Vendor:
First CVE: Apr 12, 2024 · Active for 2 years
11
Total CVEs
More Total CVEs than 90% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Derbynet over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2024
2 years ago
Most Recent CVE
Apr 18, 2024
831 days ago
CVE Severity & Scoring
Derbynet11 CVEs
45%
27%
27%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low5 (45.5%)
High0 (0.0%)
None6 (54.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-31818CRITICAL Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php component. | Apr 12, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-30923CRITICAL SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering | Apr 18, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-30922CRITICAL SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendering. | Apr 18, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-30929HIGH Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlist.php | Apr 18, 2024 | 8.0 | 23 | NO | NO |
CVE-2024-30928HIGH SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/query.slide.next.inc | Apr 18, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-30920HIGH Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php component. | Apr 18, 2024 | 7.4 | 22 | NO | NO |
CVE-2024-30925MEDIUM Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component. | Apr 18, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-30921MEDIUM Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component. | Apr 18, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-30927MEDIUM Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component. | Apr 18, 2024 | 6.3 | 17 | NO | NO |
CVE-2024-30926MEDIUM Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component. | Apr 18, 2024 | 4.6 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Derbynet
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0 | 1 | 9.8 | 1.9% | 0 | 0 |