Skip to content
Noroxi

Weaver records

18 published records for vendor weaver.

All records

18 records
  • Weaver E-Office uploadify.php unrestricted upload

    CriticalCVSS 9.8Proof of conceptEPSS 28%

    weaver · e-officeMay 11, 2023

  • Weaver OA jx2_config.ini file access

    HighCVSS 7.5Proof of conceptEPSS 54%

    weaver · e-officeMay 17, 2023

  • Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint

    CriticalCVSS 9.3Proof of conceptEPSS 20%

    weaver · e-cologyApr 7, 2026

  • An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellCont

    CriticalCVSS 9.8No exploitEPSS 1%

    weaver · e-cologyJan 19, 2024

  • An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.

    CriticalCVSS 9.8No exploitEPSS 1%

    weaver · e-officeJul 25, 2023

  • An issue in Weaver E-cology v.

    CriticalCVSS 9.8No exploitEPSS 1%

    weaver · e-cologyNov 19, 2024

  • CVE-2023-3793
    39Monitor

    Weaver e-cology HTTP POST Request filelFileDownloadForOutDoc.class sql injection

    CriticalCVSS 9.8No exploitEPSS 0%

    weaver · e-cologyJul 20, 2023

  • Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.form

    CriticalCVSS 9.8No exploitEPSS 0%

    weaver · e-cologyNov 19, 2024

  • A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files an

    CriticalCVSS 9.8No exploitEPSS 0%

    weaver · e-cologyNov 19, 2024

  • CVE-2023-2647
    37Monitor

    Weaver E-Office File Upload utility_all.php command injection

    HighCVSS 8.8No exploitEPSS 7%

    weaver · e-officeMay 11, 2023

  • Weaver E-cology SQL Injection

    HighCVSS 8.7Proof of conceptEPSS 2%

    weaver · e-cologyJun 23, 2025

  • CVE-2023-2806
    35Monitor

    Weaver e-cology API RequestInfoByXml xml external entity reference

    HighCVSS 8.8No exploitEPSS 1%

    weaver · e-cologyMay 19, 2023

  • CVE-2023-2765
    31Monitor

    Weaver OA downfile.php absolute path traversal

    HighCVSS 7.5No exploitEPSS 2%

    weaver · e-officeMay 17, 2023

  • CVE-2024-3227
    28Monitor

    Panwei eoffice OA Backend save_image.php path traversal

    HighCVSS 7.2No exploitEPSS 1%

    weaver · e-officeApr 2, 2024

  • CVE-2024-7704
    27Monitor

    Weaver e-cology Source Code ecology_dev.zip information disclosure

    MediumCVSS 6.9No exploitEPSS 1%

    weaver · e-cologyAug 12, 2024

  • An issue was discovered in eteams OA v4.0.34.

    MediumCVSS 6.5No exploitEPSS 1%

    weaver · eteams oaSep 8, 2019

  • E-cology has a directory traversal vulnerability.

    MediumCVSS 6.5No exploitEPSS 1%

    weaver · e-cologyNov 19, 2024

  • An issue was discovered in Weaver e-cology 9.0.

    MediumCVSS 6.1No exploitEPSS 1%

    weaver · e-cologyApr 30, 2019