ruvar records
26 published records for vendor ruvar.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-25517No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.ruvar · ruvaroa · CWE-89 | Critical9.8 | — | 0.7% | May 8, 2024 |
39Monitor | CVE-2024-25523No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.ruvar · ruvaroa · CWE-89 | Critical9.8 | — | 0.7% | May 8, 2024 |
39Monitor | CVE-2024-25519No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.ruvar · ruvaroa · CWE-89 | Critical9.8 | — | 0.7% | May 8, 2024 |
39Monitor | CVE-2024-25510No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_show.aruvar · ruvaroa · CWE-89 | Critical9.8 | — | 0.7% | May 7, 2024 |
39Monitor | CVE-2024-25508No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.aruvar · ruvaroa · CWE-89 | Critical9.8 | — | 0.7% | May 7, 2024 |
39Monitor | CVE-2024-25520No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.asruvar · ruvaroa · CWE-89 | Critical9.8 | — | 0.6% | May 8, 2024 |
39Monitor | CVE-2024-25525No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownloadruvar · ruvaroa · CWE-89 | Critical9.8 | — | 0.6% | May 8, 2024 |
39Monitor | CVE-2024-25529No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_sruvar · ruvaroa · CWE-89 | Critical9.8 | — | 0.6% | May 8, 2024 |
39Monitor | CVE-2024-25531No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aruvar · ruvaroa · CWE-89 | Critical9.8 | — | 0.6% | May 8, 2024 |
39Monitor | CVE-2024-25530No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condictioruvar · ruvaroa · CWE-89 | Critical9.8 | — | 0.6% | May 8, 2024 |
39Monitor | CVE-2024-25532No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.ruvar · ruvaroa · CWE-89 | Critical9.8 | — | 0.5% | May 8, 2024 |
37Monitor | CVE-2024-25533No exploit | Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx).ruvar · ruvaroa · CWE-89 | Critical9.4 | — | 0.7% | May 8, 2024 |
37Monitor | CVE-2024-25521No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_company.aspx.ruvar · ruvaroa · CWE-89 | Critical9.4 | — | 0.6% | May 8, 2024 |
37Monitor | CVE-2024-25518No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /WorkFlow/wf_get_fields_aruvar · ruvaroa · CWE-89 | Critical9.4 | — | 0.6% | May 8, 2024 |
37Monitor | CVE-2024-25524No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPlaruvar · ruvaroa · CWE-89 | Critical9.4 | — | 0.6% | May 8, 2024 |
37Monitor | CVE-2024-25511No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_new.asruvar · ruvaroa · CWE-89 | Critical9.4 | — | 0.6% | May 7, 2024 |
37Monitor | CVE-2024-25509No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_fileruvar · ruvaroa · CWE-89 | Critical9.4 | — | 0.6% | May 7, 2024 |
37Monitor | CVE-2024-25507No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /LHMail/AttachDown.asruvar · ruvaroa · CWE-89 | Critical9.4 | — | 0.6% | May 7, 2024 |
37Monitor | CVE-2024-25522No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at /WorkFlow/wf_work_fruvar · ruvaroa · CWE-89 | Critical9.4 | — | 0.6% | May 8, 2024 |
37Monitor | CVE-2024-25514No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysManage/wf_template_chruvar · ruvaroa · CWE-89 | Critical9.4 | — | 0.6% | May 7, 2024 |
37Monitor | CVE-2024-25527No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_sruvar · ruvaroa · CWE-89 | Critical9.4 | — | 0.5% | May 8, 2024 |
32Monitor | CVE-2024-25526No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /ProjectManage/pm_gatt_incruvar · ruvaroa · CWE-89 | High8.1 | — | 0.6% | May 8, 2024 |
32Monitor | CVE-2024-25512No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bulletin/AttachDownLoad.asruvar · ruvaroa · CWE-89 | High8.1 | — | 0.5% | May 7, 2024 |
31Monitor | CVE-2024-25513No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_downruvar · ruvaroa · CWE-89 | High7.8 | — | 0.3% | May 7, 2024 |
29Monitor | CVE-2024-25515No exploit | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_workruvar · ruvaroa · CWE-89 | High7.3 | — | 0.6% | May 8, 2024 |
- CVE-2024-2551739Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.
CriticalCVSS 9.8No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2552339Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.
CriticalCVSS 9.8No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2551939Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.
CriticalCVSS 9.8No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2551039Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_show.a
CriticalCVSS 9.8No exploitEPSS 1%ruvar · ruvaroaMay 7, 2024
- CVE-2024-2550839Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.a
CriticalCVSS 9.8No exploitEPSS 1%ruvar · ruvaroaMay 7, 2024
- CVE-2024-2552039Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.as
CriticalCVSS 9.8No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2552539Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload
CriticalCVSS 9.8No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2552939Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_s
CriticalCVSS 9.8No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2553139Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.a
CriticalCVSS 9.8No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2553039Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condictio
CriticalCVSS 9.8No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2553239Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.
CriticalCVSS 9.8No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2553337Monitor
Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx).
CriticalCVSS 9.4No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2552137Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_company.aspx.
CriticalCVSS 9.4No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2551837Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /WorkFlow/wf_get_fields_a
CriticalCVSS 9.4No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2552437Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPla
CriticalCVSS 9.4No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2551137Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_new.as
CriticalCVSS 9.4No exploitEPSS 1%ruvar · ruvaroaMay 7, 2024
- CVE-2024-2550937Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_file
CriticalCVSS 9.4No exploitEPSS 1%ruvar · ruvaroaMay 7, 2024
- CVE-2024-2550737Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /LHMail/AttachDown.as
CriticalCVSS 9.4No exploitEPSS 1%ruvar · ruvaroaMay 7, 2024
- CVE-2024-2552237Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at /WorkFlow/wf_work_f
CriticalCVSS 9.4No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2551437Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysManage/wf_template_ch
CriticalCVSS 9.4No exploitEPSS 1%ruvar · ruvaroaMay 7, 2024
- CVE-2024-2552737Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_s
CriticalCVSS 9.4No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2552632Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /ProjectManage/pm_gatt_inc
HighCVSS 8.1No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024
- CVE-2024-2551232Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bulletin/AttachDownLoad.as
HighCVSS 8.1No exploitEPSS 1%ruvar · ruvaroaMay 7, 2024
- CVE-2024-2551331Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_down
HighCVSS 7.8No exploitEPSS 0%ruvar · ruvaroaMay 7, 2024
- CVE-2024-2551529Monitor
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_work
HighCVSS 7.3No exploitEPSS 1%ruvar · ruvaroaMay 8, 2024