Squaredup
9 CVEs tracked since 2021. Since Feb 2021, none of them reached CISA KEV.
Squaredup CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-02 | 3 | 0 |
| 2021-03 | null or fewer | |
| 2021-04 | null or fewer | |
| 2021-05 | null or fewer | |
| 2021-06 | null or fewer | |
| 2021-07 | null or fewer | |
| 2021-08 | null or fewer | |
| 2021-09 | null or fewer | |
| 2021-10 | null or fewer | |
| 2021-11 | null or fewer | |
| 2021-12 | 6 | 0 |
Products
The products that kept showing up in Squaredup's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 13 most recently published vulnerabilities affecting Squaredup.
- CVE-2024-45180SquaredUp DS for SCOM 6.2.1.11104 allows XSS.5.4
- CVE-2022-46786SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2).5.4
- CVE-2022-46785SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).6.1
- CVE-2022-46784SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)6.1
- CVE-2021-40096A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the autho...5.4
- CVE-2021-40095An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptible to a local file inclusion vulnerability (when processing remote input in t...4.9
- CVE-2021-40094A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may allow attackers to inject malicious code into a user's device.5.4
- CVE-2021-40093A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via dashboard actions.5.4
- CVE-2021-40092A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via an SVG file.5.4
- CVE-2021-40091An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.9.8
- CVE-2020-9389A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a d...3.7
- CVE-2020-9390SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.5.4
- CVE-2020-9388CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML pa...6.5
The record
- Peak rank
- #89 in Dec 2021
- Busiest month shown
- Dec 2021, 6 CVEs
- Months with a KEV entry
- 0 since Feb 2021
- Monthly snapshots
- 2 since 2021