Advantive records
2 published records for vendor advantive.
Researcher profile
- Entered KEV
- 2 · 100%
- Weaponized
- 2 · 100%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- 35 days
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
77This week | CVE-2025-25181Weaponized | A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL advantive · veracore · CWE-89 | High7.5 | KEV | 57.3% | Feb 3, 2025 |
75This week | CVE-2024-57968Weaponized | Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessibleadvantive · veracore · CWE-434 | High8.8 | KEV | 32.3% | Feb 3, 2025 |
- CVE-2025-2518177This week
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL
HighCVSS 7.5KEVWeaponizedEPSS 57%advantive · veracoreFeb 3, 2025
- CVE-2024-5796875This week
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible
HighCVSS 8.8KEVWeaponizedEPSS 32%advantive · veracoreFeb 3, 2025