Skip to content
Noroxi

ruvar records

26 published records for vendor ruvar.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 24

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

26 records
  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.

    CriticalCVSS 9.8No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.

    CriticalCVSS 9.8No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.

    CriticalCVSS 9.8No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_show.a

    CriticalCVSS 9.8No exploitEPSS 1%

    ruvar · ruvaroaMay 7, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.a

    CriticalCVSS 9.8No exploitEPSS 1%

    ruvar · ruvaroaMay 7, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.as

    CriticalCVSS 9.8No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload

    CriticalCVSS 9.8No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_s

    CriticalCVSS 9.8No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.a

    CriticalCVSS 9.8No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condictio

    CriticalCVSS 9.8No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.

    CriticalCVSS 9.8No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx).

    CriticalCVSS 9.4No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_company.aspx.

    CriticalCVSS 9.4No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /WorkFlow/wf_get_fields_a

    CriticalCVSS 9.4No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPla

    CriticalCVSS 9.4No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_new.as

    CriticalCVSS 9.4No exploitEPSS 1%

    ruvar · ruvaroaMay 7, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_file

    CriticalCVSS 9.4No exploitEPSS 1%

    ruvar · ruvaroaMay 7, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /LHMail/AttachDown.as

    CriticalCVSS 9.4No exploitEPSS 1%

    ruvar · ruvaroaMay 7, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at /WorkFlow/wf_work_f

    CriticalCVSS 9.4No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysManage/wf_template_ch

    CriticalCVSS 9.4No exploitEPSS 1%

    ruvar · ruvaroaMay 7, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_s

    CriticalCVSS 9.4No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /ProjectManage/pm_gatt_inc

    HighCVSS 8.1No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bulletin/AttachDownLoad.as

    HighCVSS 8.1No exploitEPSS 1%

    ruvar · ruvaroaMay 7, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_down

    HighCVSS 7.8No exploitEPSS 0%

    ruvar · ruvaroaMay 7, 2024

  • RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_work

    HighCVSS 7.3No exploitEPSS 1%

    ruvar · ruvaroaMay 8, 2024