1E records
12 published records for vendor 1e.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 41.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-20 Improper Input Validation3
- CWE-428 Unquoted Search Path or Element2
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-45162No exploit | Blind SQL vulnerability in 1E platform1e · platform · CWE-89 | Critical9.8 | — | 0.6% | Oct 13, 2023 |
35Monitor | CVE-2020-16268No exploit | The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the1e · client · CWE-74 | High8.8 | — | 1.3% | Dec 29, 2020 |
35Monitor | CVE-2020-27645No exploit | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.1e · client · CWE-428 | High8.8 | — | 1.2% | Dec 29, 2020 |
35Monitor | CVE-2020-27644No exploit | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.1e · client · CWE-428 | High8.8 | — | 1.2% | Dec 29, 2020 |
35Monitor | CVE-2023-45160No exploit | Elevated Temp Directory Execution in 1E Client1e · client · CWE-552 | High8.8 | — | 0.7% | Oct 5, 2023 |
33Monitor | CVE-2023-45159No exploit | 1E Client installer can perform arbitrary file deletion on protected files1e · client · CWE-59 | High8.4 | — | 0.2% | Oct 5, 2023 |
31Monitor | CVE-2025-1683No exploit | Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion1e · platform · CWE-59 | High7.8 | — | 0.2% | Mar 12, 2025 |
28Monitor | CVE-2023-45163No exploit | 1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution1e · platform · CWE-20 | High7.2 | — | 0.9% | Nov 6, 2023 |
28Monitor | CVE-2023-45161No exploit | 1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution1e · platform · CWE-20 | High7.2 | — | 0.8% | Nov 6, 2023 |
28Monitor | CVE-2023-5964No exploit | 1E-Exchange-DisplayMessage instruction allows for arbitrary code execution1e · platform · CWE-20 | High7.2 | — | 0.8% | Nov 6, 2023 |
26Monitor | CVE-2020-27643No exploit | The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and m1e · client · CWE-59 | Medium6.5 | — | 1.4% | Dec 29, 2020 |
24Monitor | CVE-2024-7211No exploit | The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.1e · platform · CWE-601 | Medium6.1 | — | 0.2% | Aug 1, 2024 |
- CVE-2023-4516239Monitor
Blind SQL vulnerability in 1E platform
CriticalCVSS 9.8No exploitEPSS 1%1e · platformOct 13, 2023
- CVE-2020-1626835Monitor
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the
HighCVSS 8.8No exploitEPSS 1%1e · clientDec 29, 2020
- CVE-2020-2764535Monitor
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.
HighCVSS 8.8No exploitEPSS 1%1e · clientDec 29, 2020
- CVE-2020-2764435Monitor
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.
HighCVSS 8.8No exploitEPSS 1%1e · clientDec 29, 2020
- CVE-2023-4516035Monitor
Elevated Temp Directory Execution in 1E Client
HighCVSS 8.8No exploitEPSS 1%1e · clientOct 5, 2023
- CVE-2023-4515933Monitor
1E Client installer can perform arbitrary file deletion on protected files
HighCVSS 8.4No exploitEPSS 0%1e · clientOct 5, 2023
- CVE-2025-168331Monitor
Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion
HighCVSS 7.8No exploitEPSS 0%1e · platformMar 12, 2025
- CVE-2023-4516328Monitor
1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution
HighCVSS 7.2No exploitEPSS 1%1e · platformNov 6, 2023
- CVE-2023-4516128Monitor
1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution
HighCVSS 7.2No exploitEPSS 1%1e · platformNov 6, 2023
- CVE-2023-596428Monitor
1E-Exchange-DisplayMessage instruction allows for arbitrary code execution
HighCVSS 7.2No exploitEPSS 1%1e · platformNov 6, 2023
- CVE-2020-2764326Monitor
The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and m
MediumCVSS 6.5No exploitEPSS 1%1e · clientDec 29, 2020
- CVE-2024-721124Monitor
The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.
MediumCVSS 6.1No exploitEPSS 0%1e · platformAug 1, 2024