Vulnerabilidades en Priority
23 resultadosAnálisis Vexday
Priority possui 14 vulnerabilidades catalogadas, das quais 2 são críticas, mas nenhuma está sob ataque ativo conhecido. A fraqueza dominante é exposição de informação (CWE-200), indicando problemas de controle de acesso a dados sensíveis. Sem publicações recentes nos últimos 90 dias, o risco atual é estável e de baixa urgência operacional.
CVE-2023-23459CRITICALPriority Windows – Command Execution via SQL Injection EPSS 0.9%CVE-2023-23460CRITICALPriority Web – Authentication bypass EPSS 0.7%CVE-2022-23173MEDIUMPriority - Priority web Insecure direct object references (IDOR)EPSS 0.5%CVE-2024-47922HIGHPriority – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.5%CVE-2022-23172MEDIUMPriority - Priority User EnumerationEPSS 0.4%CVE-2024-41696HIGHPriority PRI WEB Portal Add-On for Priority ERP on prem – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.4%CVE-2024-41699MEDIUMPriority – CWE-552: Files or Directories Accessible to External PartiesEPSS 0.3%CVE-2024-41698MEDIUMPriority – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.3%CVE-2025-55061HIGHPriority - CWE-434 Unrestricted Upload of File with Dangerous TypeEPSS 0.3%CVE-2026-59504CRITICALPriority – CWE-602: Client-Side Enforcement of Server-Side SecurityEPSS 0.3%CVE-2026-59503CRITICALPriority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.3%CVE-2026-59500CRITICALPriority - CWE-287: Improper AuthenticationEPSS 0.3%CVE-2026-59506CRITICALPriority – CWE-306: Missing Authentication for Critical FunctionEPSS 0.3%CVE-2026-59505HIGHPriority - CWE-284: Improper Access ControlEPSS 0.3%CVE-2024-41697MEDIUMPriority – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)EPSS 0.3%CVE-2026-59499HIGHPriority – CWE-200: Exposure of Sensitive Information to an Unauthorized ActorEPSS 0.2%CVE-2026-59507CRITICALPriority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access ControlEPSS 0.2%CVE-2026-59501HIGHPriority – CWE-284: Improper Access ControlEPSS 0.2%CVE-2026-59502MEDIUMPriority - CWE-203: Observable DiscrepancyEPSS 0.2%CVE-2025-55062MEDIUMPriority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')EPSS 0.2%