Записи 1E
12 опубликованных записей вендора 1e.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 41,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-20 Improper Input Validation3
- CWE-428 Unquoted Search Path or Element2
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-45162Эксплойта нет | Blind SQL vulnerability in 1E platform1e · platform · CWE-89 | Критическая9,8 | — | 0,6 % | 13 окт. 2023 г. |
35Наблюдать | CVE-2020-16268Эксплойта нет | The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the1e · client · CWE-74 | Высокая8,8 | — | 1,3 % | 29 дек. 2020 г. |
35Наблюдать | CVE-2020-27645Эксплойта нет | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.1e · client · CWE-428 | Высокая8,8 | — | 1,2 % | 29 дек. 2020 г. |
35Наблюдать | CVE-2020-27644Эксплойта нет | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.1e · client · CWE-428 | Высокая8,8 | — | 1,2 % | 29 дек. 2020 г. |
35Наблюдать | CVE-2023-45160Эксплойта нет | Elevated Temp Directory Execution in 1E Client1e · client · CWE-552 | Высокая8,8 | — | 0,7 % | 5 окт. 2023 г. |
33Наблюдать | CVE-2023-45159Эксплойта нет | 1E Client installer can perform arbitrary file deletion on protected files1e · client · CWE-59 | Высокая8,4 | — | 0,2 % | 5 окт. 2023 г. |
31Наблюдать | CVE-2025-1683Эксплойта нет | Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion1e · platform · CWE-59 | Высокая7,8 | — | 0,2 % | 12 мар. 2025 г. |
28Наблюдать | CVE-2023-45163Эксплойта нет | 1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution1e · platform · CWE-20 | Высокая7,2 | — | 0,9 % | 6 нояб. 2023 г. |
28Наблюдать | CVE-2023-45161Эксплойта нет | 1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution1e · platform · CWE-20 | Высокая7,2 | — | 0,8 % | 6 нояб. 2023 г. |
28Наблюдать | CVE-2023-5964Эксплойта нет | 1E-Exchange-DisplayMessage instruction allows for arbitrary code execution1e · platform · CWE-20 | Высокая7,2 | — | 0,8 % | 6 нояб. 2023 г. |
26Наблюдать | CVE-2020-27643Эксплойта нет | The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and m1e · client · CWE-59 | Средняя6,5 | — | 1,4 % | 29 дек. 2020 г. |
24Наблюдать | CVE-2024-7211Эксплойта нет | The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.1e · platform · CWE-601 | Средняя6,1 | — | 0,2 % | 1 авг. 2024 г. |
- CVE-2023-4516239Наблюдать
Blind SQL vulnerability in 1E platform
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %1e · platform13 окт. 2023 г.
- CVE-2020-1626835Наблюдать
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %1e · client29 дек. 2020 г.
- CVE-2020-2764535Наблюдать
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %1e · client29 дек. 2020 г.
- CVE-2020-2764435Наблюдать
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %1e · client29 дек. 2020 г.
- CVE-2023-4516035Наблюдать
Elevated Temp Directory Execution in 1E Client
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %1e · client5 окт. 2023 г.
- CVE-2023-4515933Наблюдать
1E Client installer can perform arbitrary file deletion on protected files
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %1e · client5 окт. 2023 г.
- CVE-2025-168331Наблюдать
Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %1e · platform12 мар. 2025 г.
- CVE-2023-4516328Наблюдать
1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %1e · platform6 нояб. 2023 г.
- CVE-2023-4516128Наблюдать
1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %1e · platform6 нояб. 2023 г.
- CVE-2023-596428Наблюдать
1E-Exchange-DisplayMessage instruction allows for arbitrary code execution
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %1e · platform6 нояб. 2023 г.
- CVE-2020-2764326Наблюдать
The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and m
СредняяCVSS 6,5Эксплойта нетEPSS 1 %1e · client29 дек. 2020 г.
- CVE-2024-721124Наблюдать
The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %1e · platform1 авг. 2024 г.