Tecnick records
26 published records for vendor tecnick.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 7.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2018-17057Proof of concept | An issue was discovered in TCPDF before 6.2.22.tecnick · tcpdf · CWE-502 | Critical9.8 | — | 26.2% | Sep 14, 2018 |
32Monitor | CVE-2021-20114Proof of concept | When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directecnick · tcexam · CWE-425 | High7.5 | — | 6.0% | Jul 30, 2021 |
31Monitor | CVE-2009-4747Proof of concept | PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attatecnick · aiocp · CWE-94 | High7.5 | — | 3.0% | Mar 26, 2010 |
31Monitor | CVE-2009-3220Proof of concept | PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute artecnick · aiocp · CWE-94 | High7.5 | — | 2.1% | Sep 16, 2009 |
29Monitor | CVE-2010-2153Proof of concept | Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackertecnick · tcexam | Medium6.8 | — | 7.5% | Jun 3, 2010 |
29Monitor | CVE-2020-5745No exploit | Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users itecnick · tcexam · CWE-352 | High7.4 | — | 0.8% | May 7, 2020 |
28Monitor | CVE-2012-4237Proof of concept | Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to exetecnick · tcexam · CWE-89 | Medium6.8 | — | 2.4% | Aug 20, 2012 |
26Monitor | CVE-2023-6554No exploit | Missing authorisation in TCExamtecnick · tcexam · CWE-862 | Medium6.5 | — | 0.6% | Jan 11, 2024 |
24Monitor | CVE-2012-4601No exploit | Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permitecnick · tcexam · CWE-89 | Medium6.0 | — | 1.6% | Nov 23, 2012 |
24Monitor | CVE-2020-5750No exploit | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)tecnick · tcexam · CWE-79 | Medium6.1 | — | 1.1% | May 7, 2020 |
24Monitor | CVE-2020-5748No exploit | Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)tecnick · tcexam · CWE-79 | Medium6.1 | — | 1.1% | May 7, 2020 |
24Monitor | CVE-2021-20115No exploit | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3.tecnick · tcexam · CWE-79 | Medium6.1 | — | 0.9% | Aug 5, 2021 |
24Monitor | CVE-2021-20116No exploit | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4.tecnick · tcexam · CWE-79 | Medium6.1 | — | 0.9% | Aug 5, 2021 |
24Monitor | CVE-2018-13422No exploit | TCExam before 14.1.2 has XSS via an ff_ or xl_ field.tecnick · tcexam · CWE-79 | Medium6.1 | — | 0.8% | Jul 7, 2018 |
21Monitor | CVE-2021-20113No exploit | An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1.tecnick · tcexam · CWE-203 | Medium5.3 | — | 1.3% | Jul 30, 2021 |
21Monitor | CVE-2020-5747No exploit | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Medium5.4 | — | 0.7% | May 7, 2020 |
21Monitor | CVE-2020-5746No exploit | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Medium5.4 | — | 0.7% | May 7, 2020 |
21Monitor | CVE-2020-5749No exploit | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Medium5.4 | — | 0.7% | May 7, 2020 |
21Monitor | CVE-2020-5751No exploit | Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) atecnick · tcexam · CWE-79 | Medium5.4 | — | 0.7% | May 7, 2020 |
21Monitor | CVE-2021-20112No exploit | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.tecnick · tcexam · CWE-79 | Medium5.4 | — | 0.6% | Jul 30, 2021 |
21Monitor | CVE-2021-20111No exploit | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.tecnick · tcexam · CWE-79 | Medium5.4 | — | 0.6% | Jul 30, 2021 |
20Monitor | CVE-2011-3806No exploit | TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation tecnick · tcexam · CWE-200 | Medium5.0 | — | 1.2% | Sep 23, 2011 |
19Monitor | CVE-2020-5744No exploit | Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.tecnick · tcexam · CWE-22 | Medium4.9 | — | 1.4% | May 7, 2020 |
18Monitor | CVE-2012-4602No exploit | Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow retecnick · tcexam · CWE-79 | Medium4.3 | — | 1.8% | Nov 23, 2012 |
17Monitor | CVE-2020-5743No exploit | Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they dontecnick · tcexam · CWE-639 | Medium4.3 | — | 0.8% | May 7, 2020 |
- CVE-2018-1705747Plan
An issue was discovered in TCPDF before 6.2.22.
CriticalCVSS 9.8Proof of conceptEPSS 26%tecnick · tcpdfSep 14, 2018
- CVE-2021-2011432Monitor
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ direc
HighCVSS 7.5Proof of conceptEPSS 6%tecnick · tcexamJul 30, 2021
- CVE-2009-474731Monitor
PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote atta
HighCVSS 7.5Proof of conceptEPSS 3%tecnick · aiocpMar 26, 2010
- CVE-2009-322031Monitor
PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute ar
HighCVSS 7.5Proof of conceptEPSS 2%tecnick · aiocpSep 16, 2009
- CVE-2010-215329Monitor
Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attacker
MediumCVSS 6.8Proof of conceptEPSS 7%tecnick · tcexamJun 3, 2010
- CVE-2020-574529Monitor
Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users i
HighCVSS 7.4No exploitEPSS 1%tecnick · tcexamMay 7, 2020
- CVE-2012-423728Monitor
Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to exe
MediumCVSS 6.8Proof of conceptEPSS 2%tecnick · tcexamAug 20, 2012
- CVE-2023-655426Monitor
Missing authorisation in TCExam
MediumCVSS 6.5No exploitEPSS 1%tecnick · tcexamJan 11, 2024
- CVE-2012-460124Monitor
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permi
MediumCVSS 6.0No exploitEPSS 2%tecnick · tcexamNov 23, 2012
- CVE-2020-575024Monitor
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)
MediumCVSS 6.1No exploitEPSS 1%tecnick · tcexamMay 7, 2020
- CVE-2020-574824Monitor
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS)
MediumCVSS 6.1No exploitEPSS 1%tecnick · tcexamMay 7, 2020
- CVE-2021-2011524Monitor
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3.
MediumCVSS 6.1No exploitEPSS 1%tecnick · tcexamAug 5, 2021
- CVE-2021-2011624Monitor
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4.
MediumCVSS 6.1No exploitEPSS 1%tecnick · tcexamAug 5, 2021
- CVE-2018-1342224Monitor
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.
MediumCVSS 6.1No exploitEPSS 1%tecnick · tcexamJul 7, 2018
- CVE-2021-2011321Monitor
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1.
MediumCVSS 5.3No exploitEPSS 1%tecnick · tcexamJul 30, 2021
- CVE-2020-574721Monitor
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
MediumCVSS 5.4No exploitEPSS 1%tecnick · tcexamMay 7, 2020
- CVE-2020-574621Monitor
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
MediumCVSS 5.4No exploitEPSS 1%tecnick · tcexamMay 7, 2020
- CVE-2020-574921Monitor
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
MediumCVSS 5.4No exploitEPSS 1%tecnick · tcexamMay 7, 2020
- CVE-2020-575121Monitor
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) a
MediumCVSS 5.4No exploitEPSS 1%tecnick · tcexamMay 7, 2020
- CVE-2021-2011221Monitor
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.
MediumCVSS 5.4No exploitEPSS 1%tecnick · tcexamJul 30, 2021
- CVE-2021-2011121Monitor
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1.
MediumCVSS 5.4No exploitEPSS 1%tecnick · tcexamJul 30, 2021
- CVE-2011-380620Monitor
TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
MediumCVSS 5.0No exploitEPSS 1%tecnick · tcexamSep 23, 2011
- CVE-2020-574419Monitor
Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
MediumCVSS 4.9No exploitEPSS 1%tecnick · tcexamMay 7, 2020
- CVE-2012-460218Monitor
Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow re
MediumCVSS 4.3No exploitEPSS 2%tecnick · tcexamNov 23, 2012
- CVE-2020-574317Monitor
Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don
MediumCVSS 4.3No exploitEPSS 1%tecnick · tcexamMay 7, 2020