nsclient records
3 published records for vendor nsclient.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 66.7%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-428 Unquoted Search Path or Element1
- CWE-522 Insufficiently Protected Credentials1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2018-6384No exploit | Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with elnsclient · nsclient\+\+ · CWE-428 | High7.8 | — | 0.8% | Jan 31, 2018 |
30Monitor | CVE-2025-34079Weaponized | NSClient++ Authenticated Remote Code Execution via ExternalScripts APInsclient · nsclient\+\+ · CWE-94 | High7.5 | — | 1.6% | Jul 2, 2025 |
29Monitor | CVE-2025-34078Weaponized | NSClient++ 0.5.2.35 Local Privilege Escalation via ExternalScripts and Web Interfacensclient · nsclient\+\+ · CWE-522 | High7.3 | — | 0.7% | Jul 2, 2025 |
- CVE-2018-638431Monitor
Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with el
HighCVSS 7.8No exploitEPSS 1%nsclient · nsclient\+\+Jan 31, 2018
- CVE-2025-3407930Monitor
NSClient++ Authenticated Remote Code Execution via ExternalScripts API
HighCVSS 7.5WeaponizedEPSS 2%nsclient · nsclient\+\+Jul 2, 2025
- CVE-2025-3407829Monitor
NSClient++ 0.5.2.35 Local Privilege Escalation via ExternalScripts and Web Interface
HighCVSS 7.3WeaponizedEPSS 1%nsclient · nsclient\+\+Jul 2, 2025