Перейти к содержимому
Noroxi

Записи 1E

12 опубликованных записей вендора 1e.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
41,7 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

12 записей
  • CVE-2023-45162
    39Наблюдать

    Blind SQL vulnerability in 1E platform

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    1e · platform13 окт. 2023 г.

  • CVE-2020-16268
    35Наблюдать

    The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    1e · client29 дек. 2020 г.

  • CVE-2020-27645
    35Наблюдать

    The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    1e · client29 дек. 2020 г.

  • CVE-2020-27644
    35Наблюдать

    The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    1e · client29 дек. 2020 г.

  • CVE-2023-45160
    35Наблюдать

    Elevated Temp Directory Execution in 1E Client

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    1e · client5 окт. 2023 г.

  • CVE-2023-45159
    33Наблюдать

    1E Client installer can perform arbitrary file deletion on protected files

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    1e · client5 окт. 2023 г.

  • CVE-2025-1683
    31Наблюдать

    Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    1e · platform12 мар. 2025 г.

  • CVE-2023-45163
    28Наблюдать

    1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    1e · platform6 нояб. 2023 г.

  • CVE-2023-45161
    28Наблюдать

    1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    1e · platform6 нояб. 2023 г.

  • CVE-2023-5964
    28Наблюдать

    1E-Exchange-DisplayMessage instruction allows for arbitrary code execution

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    1e · platform6 нояб. 2023 г.

  • CVE-2020-27643
    26Наблюдать

    The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and m

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    1e · client29 дек. 2020 г.

  • CVE-2024-7211
    24Наблюдать

    The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    1e · platform1 авг. 2024 г.