simple-help records
6 published records for vendor simple-help.
Researcher profile
- Entered KEV
- 4 · 66.7%
- Weaponized
- 4 · 66.7%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- 247 days
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
89Now | CVE-2024-57727Weaponized | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated resimple-help · simplehelp · CWE-22 | High7.5 | KEV | 96.6% | Jan 15, 2025 |
89Now | CVE-2024-57726Weaponized | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excesimple-help · simplehelp · CWE-862 | Critical9.9 | KEV | 66.6% | Jan 15, 2025 |
77This week | CVE-2024-57728Weaponized | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading asimple-help · simplehelp · CWE-59 | High7.2 | KEV | 64.7% | Jan 15, 2025 |
70This week | CVE-2026-48558Weaponized | SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verificationsimple-help · simplehelp · CWE-347 | Critical9.5 | KEV | 5.7% | Jun 12, 2026 |
35Monitor | CVE-2025-36727No exploit | SimpleHelp Inclusion of functionality from untrusted control spheresimple-help · simplehelp · CWE-829 | High8.8 | — | 0.4% | Jul 25, 2025 |
35Monitor | CVE-2025-36728No exploit | SimpleHelp Cross Site Request Forgerysimple-help · simplehelp · CWE-352 | High8.8 | — | 0.2% | Jul 25, 2025 |
- CVE-2024-5772789Now
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated re
HighCVSS 7.5KEVWeaponizedEPSS 97%simple-help · simplehelpJan 15, 2025
- CVE-2024-5772689Now
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with exce
CriticalCVSS 9.9KEVWeaponizedEPSS 67%simple-help · simplehelpJan 15, 2025
- CVE-2024-5772877This week
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a
HighCVSS 7.2KEVWeaponizedEPSS 65%simple-help · simplehelpJan 15, 2025
- CVE-2026-4855870This week
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
CriticalCVSS 9.5KEVWeaponizedEPSS 6%simple-help · simplehelpJun 12, 2026
- CVE-2025-3672735Monitor
SimpleHelp Inclusion of functionality from untrusted control sphere
HighCVSS 8.8No exploitEPSS 0%simple-help · simplehelpJul 25, 2025
- CVE-2025-3672835Monitor
SimpleHelp Cross Site Request Forgery
HighCVSS 8.8No exploitEPSS 0%simple-help · simplehelpJul 25, 2025