datev records
4 published records for vendor datev.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-426 Untrusted Search Path1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2010-0689No exploit | The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allodatev · base system | Critical10.0 | — | 6.0% | Feb 26, 2010 |
38Monitor | CVE-2011-5158No exploit | Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 adatev · grundpaket basis · CWE-426 | Critical9.3 | — | 2.0% | Sep 7, 2012 |
24Monitor | CVE-2023-33387No exploit | A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allowdatev · eg personal-management system comfort\/comfort plus · CWE-79 | Medium6.1 | — | 0.5% | Jun 22, 2023 |
18Monitor | CVE-2003-1169Proof of concept | DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access resdatev · nutzungskontrolle | Medium4.6 | — | 0.8% | Dec 31, 2003 |
- CVE-2010-068942Plan
The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allo
CriticalCVSS 10.0No exploitEPSS 6%datev · base systemFeb 26, 2010
- CVE-2011-515838Monitor
Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 a
CriticalCVSS 9.3No exploitEPSS 2%datev · grundpaket basisSep 7, 2012
- CVE-2023-3338724Monitor
A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allow
MediumCVSS 6.1No exploitEPSS 1%datev · eg personal-management system comfort\/comfort plusJun 22, 2023
- CVE-2003-116918Monitor
DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access res
MediumCVSS 4.6Proof of conceptEPSS 1%datev · nutzungskontrolleDec 31, 2003