İçeriğe atla
Noroxi

1E kayıtları

1e üreticisine ait 12 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%41,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

12 kayıt
  • CVE-2023-45162
    39İzleyin

    Blind SQL vulnerability in 1E platform

    KritikCVSS 9,8İstismar yokEPSS %1

    1e · platform13 Eki 2023

  • CVE-2020-16268
    35İzleyin

    The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the

    YüksekCVSS 8,8İstismar yokEPSS %1

    1e · client29 Ara 2020

  • CVE-2020-27645
    35İzleyin

    The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.

    YüksekCVSS 8,8İstismar yokEPSS %1

    1e · client29 Ara 2020

  • CVE-2020-27644
    35İzleyin

    The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.

    YüksekCVSS 8,8İstismar yokEPSS %1

    1e · client29 Ara 2020

  • CVE-2023-45160
    35İzleyin

    Elevated Temp Directory Execution in 1E Client

    YüksekCVSS 8,8İstismar yokEPSS %1

    1e · client5 Eki 2023

  • CVE-2023-45159
    33İzleyin

    1E Client installer can perform arbitrary file deletion on protected files

    YüksekCVSS 8,4İstismar yokEPSS %0

    1e · client5 Eki 2023

  • CVE-2025-1683
    31İzleyin

    Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion

    YüksekCVSS 7,8İstismar yokEPSS %0

    1e · platform12 Mar 2025

  • CVE-2023-45163
    28İzleyin

    1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution

    YüksekCVSS 7,2İstismar yokEPSS %1

    1e · platform6 Kas 2023

  • CVE-2023-45161
    28İzleyin

    1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution

    YüksekCVSS 7,2İstismar yokEPSS %1

    1e · platform6 Kas 2023

  • CVE-2023-5964
    28İzleyin

    1E-Exchange-DisplayMessage instruction allows for arbitrary code execution

    YüksekCVSS 7,2İstismar yokEPSS %1

    1e · platform6 Kas 2023

  • CVE-2020-27643
    26İzleyin

    The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and m

    OrtaCVSS 6,5İstismar yokEPSS %1

    1e · client29 Ara 2020

  • CVE-2024-7211
    24İzleyin

    The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.

    OrtaCVSS 6,1İstismar yokEPSS %0

    1e · platform1 Ağu 2024