Записи newgensoft
6 опубликованных записей вендора newgensoft.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-284 Improper Access Control1
- CWE-669 Incorrect Resource Transfer Between Spheres1
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
33Наблюдать | CVE-2020-35737Proof of concept | In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating thenewgensoft · egov | Высокая7,5 | — | 10,4 % | 30 дек. 2020 г. |
32Наблюдать | CVE-2025-65742Proof of concept | An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive innewgensoft · omnidocs · CWE-862 | Высокая8,2 | — | 0,3 % | 15 дек. 2025 г. |
31Наблюдать | CVE-2011-3645Proof of concept | Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jnewgensoft · omnidocs · CWE-264 | Высокая7,5 | — | 2,6 % | 27 сент. 2011 г. |
31Наблюдать | CVE-2018-17791Эксплойта нет | Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validnewgensoft · omniflow intelligent business process suite · CWE-669 | Высокая7,5 | — | 1,9 % | 21 авг. 2019 г. |
30Наблюдать | CVE-2010-0701Proof of concept | SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commandsnewgensoft · omnidocs · CWE-89 | Высокая7,5 | — | 1,2 % | 23 февр. 2010 г. |
30Наблюдать | CVE-2025-69908Эксплойта нет | An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a pubnewgensoft · omniapp · CWE-284 | Высокая7,5 | — | 0,4 % | 23 янв. 2026 г. |
- CVE-2020-3573733Наблюдать
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %newgensoft · egov30 дек. 2020 г.
- CVE-2025-6574232Наблюдать
An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive in
ВысокаяCVSS 8,2Proof of conceptEPSS 0 %newgensoft · omnidocs15 дек. 2025 г.
- CVE-2011-364531Наблюдать
Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.j
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %newgensoft · omnidocs27 сент. 2011 г.
- CVE-2018-1779131Наблюдать
Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side valid
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %newgensoft · omniflow intelligent business process suite21 авг. 2019 г.
- CVE-2010-070130Наблюдать
SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %newgensoft · omnidocs23 февр. 2010 г.
- CVE-2025-6990830Наблюдать
An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a pub
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %newgensoft · omniapp23 янв. 2026 г.