Skip to content
Noroxi

1E records

12 published records for vendor 1e.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
41.7%
Median publish → KEV
No record has entered KEV

All records

12 records
  • Blind SQL vulnerability in 1E platform

    CriticalCVSS 9.8No exploitEPSS 1%

    1e · platformOct 13, 2023

  • The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the

    HighCVSS 8.8No exploitEPSS 1%

    1e · clientDec 29, 2020

  • The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.

    HighCVSS 8.8No exploitEPSS 1%

    1e · clientDec 29, 2020

  • The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.

    HighCVSS 8.8No exploitEPSS 1%

    1e · clientDec 29, 2020

  • Elevated Temp Directory Execution in 1E Client

    HighCVSS 8.8No exploitEPSS 1%

    1e · clientOct 5, 2023

  • 1E Client installer can perform arbitrary file deletion on protected files

    HighCVSS 8.4No exploitEPSS 0%

    1e · clientOct 5, 2023

  • CVE-2025-1683
    31Monitor

    Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion

    HighCVSS 7.8No exploitEPSS 0%

    1e · platformMar 12, 2025

  • 1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution

    HighCVSS 7.2No exploitEPSS 1%

    1e · platformNov 6, 2023

  • 1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution

    HighCVSS 7.2No exploitEPSS 1%

    1e · platformNov 6, 2023

  • CVE-2023-5964
    28Monitor

    1E-Exchange-DisplayMessage instruction allows for arbitrary code execution

    HighCVSS 7.2No exploitEPSS 1%

    1e · platformNov 6, 2023

  • The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and m

    MediumCVSS 6.5No exploitEPSS 1%

    1e · clientDec 29, 2020

  • CVE-2024-7211
    24Monitor

    The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.

    MediumCVSS 6.1No exploitEPSS 0%

    1e · platformAug 1, 2024