abbyy records
4 published records for vendor abbyy.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2018-13791No exploit | The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12abbyy · flexicapture · CWE-732 | Critical9.8 | — | 1.1% | Jul 9, 2018 |
39Monitor | CVE-2018-13792No exploit | Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attackerabbyy · flexicapture · CWE-89 | Critical9.8 | — | 1.0% | Feb 9, 2019 |
35Monitor | CVE-2018-13793No exploit | Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 exist in Web Vabbyy · flexicapture · CWE-352 | High8.8 | — | 0.5% | Jul 9, 2018 |
31Monitor | CVE-2019-20383No exploit | ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via abbyy · finereader · CWE-59 | High7.8 | — | 0.5% | Aug 13, 2020 |
- CVE-2018-1379139Monitor
The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12
CriticalCVSS 9.8No exploitEPSS 1%abbyy · flexicaptureJul 9, 2018
- CVE-2018-1379239Monitor
Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker
CriticalCVSS 9.8No exploitEPSS 1%abbyy · flexicaptureFeb 9, 2019
- CVE-2018-1379335Monitor
Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 exist in Web V
HighCVSS 8.8No exploitEPSS 0%abbyy · flexicaptureJul 9, 2018
- CVE-2019-2038331Monitor
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via
HighCVSS 7.8No exploitEPSS 0%abbyy · finereaderAug 13, 2020