WPS records
6 published records for vendor wps.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-20 Improper Input Validation1
- CWE-310 Cryptographic Issues1
- CWE-416 Use After Free1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2022-24934Proof of concept | wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry.wps · wps office | Critical9.8 | — | 20.5% | Mar 23, 2022 |
41Plan | CVE-2005-2290No exploit | wps_shop.cgi in WPS Web Portal System 0.7.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art anwps · web portal system | Critical10.0 | — | 3.2% | Jul 18, 2005 |
32Monitor | CVE-2014-2271No exploit | cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls bacwps · wps office · CWE-20 | High8.1 | — | 1.5% | Jan 14, 2020 |
31Monitor | CVE-2021-40399No exploit | An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351.wps · wps office · CWE-416 | High7.8 | — | 1.3% | May 12, 2022 |
26Monitor | CVE-2018-6390No exploit | The WStr::assign function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 does not validate the size of the source memory blocwps · wps office · CWE-119 | Medium6.5 | — | 1.1% | Jan 29, 2018 |
21Monitor | CVE-2014-6692No exploit | The Kingsoft Clip (Office Tool) (aka cn.wps.clip) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which awps · kingsoft clip \(office tool\) · CWE-310 | Medium5.4 | — | 0.3% | Sep 23, 2014 |
- CVE-2022-2493445Plan
wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry.
CriticalCVSS 9.8Proof of conceptEPSS 20%wps · wps officeMar 23, 2022
- CVE-2005-229041Plan
wps_shop.cgi in WPS Web Portal System 0.7.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art an
CriticalCVSS 10.0No exploitEPSS 3%wps · web portal systemJul 18, 2005
- CVE-2014-227132Monitor
cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls bac
HighCVSS 8.1No exploitEPSS 2%wps · wps officeJan 14, 2020
- CVE-2021-4039931Monitor
An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351.
HighCVSS 7.8No exploitEPSS 1%wps · wps officeMay 12, 2022
- CVE-2018-639026Monitor
The WStr::assign function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 does not validate the size of the source memory bloc
MediumCVSS 6.5No exploitEPSS 1%wps · wps officeJan 29, 2018
- CVE-2014-669221Monitor
The Kingsoft Clip (Office Tool) (aka cn.wps.clip) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which a
MediumCVSS 5.4No exploitEPSS 0%wps · kingsoft clip \(office tool\)Sep 23, 2014