Serosoft records
7 published records for vendor serosoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-862 Missing Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-284 Improper Access Control1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2025-27583No exploit | Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academia Student Informatiserosoft · academia student information system · CWE-862 | Critical9.1 | — | 0.4% | Mar 2, 2025 |
32Monitor | CVE-2025-25950No exploit | Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS)serosoft · academia student information system · CWE-284 | High8.1 | — | 0.4% | Mar 2, 2025 |
30Monitor | CVE-2025-25951No exploit | An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Informatserosoft · academia student information system · CWE-200 | High7.5 | — | 0.4% | Mar 2, 2025 |
26Monitor | CVE-2025-25953No exploit | Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token expserosoft · academia student information system · CWE-862 | Medium6.5 | — | 0.4% | Mar 2, 2025 |
26Monitor | CVE-2025-25952No exploit | An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Sserosoft · academia student information system · CWE-639 | Medium6.5 | — | 0.4% | Mar 2, 2025 |
21Monitor | CVE-2025-27584No exploit | A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 alserosoft · academia student information system · CWE-79 | Medium5.4 | — | 0.2% | Mar 2, 2025 |
21Monitor | CVE-2025-27585No exploit | A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 alserosoft · academia student information system · CWE-79 | Medium5.4 | — | 0.2% | Mar 2, 2025 |
- CVE-2025-2758336Monitor
Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academia Student Informati
CriticalCVSS 9.1No exploitEPSS 0%serosoft · academia student information systemMar 2, 2025
- CVE-2025-2595032Monitor
Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS)
HighCVSS 8.1No exploitEPSS 0%serosoft · academia student information systemMar 2, 2025
- CVE-2025-2595130Monitor
An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Informat
HighCVSS 7.5No exploitEPSS 0%serosoft · academia student information systemMar 2, 2025
- CVE-2025-2595326Monitor
Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exp
MediumCVSS 6.5No exploitEPSS 0%serosoft · academia student information systemMar 2, 2025
- CVE-2025-2595226Monitor
An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia S
MediumCVSS 6.5No exploitEPSS 0%serosoft · academia student information systemMar 2, 2025
- CVE-2025-2758421Monitor
A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 al
MediumCVSS 5.4No exploitEPSS 0%serosoft · academia student information systemMar 2, 2025
- CVE-2025-2758521Monitor
A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 al
MediumCVSS 5.4No exploitEPSS 0%serosoft · academia student information systemMar 2, 2025