Записи QDOCS
6 опубликованных записей вендора qdocs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 16,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-5495Эксплойта нет | QDocs Smart School HTTP POST Request sql injectionqdocs · smart school · CWE-89 | Критическая9,8 | — | 1,1 % | 10 окт. 2023 г. |
28Наблюдать | CVE-2025-60500Proof of concept | QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictiqdocs · smart school · CWE-434 | Высокая7,2 | — | 0,5 % | 21 окт. 2025 г. |
24Наблюдать | CVE-2024-34240Эксплойта нет | QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin functions related to addqdocs · smart school · CWE-79 | Средняя6,1 | — | 0,4 % | 21 мая 2024 г. |
21Наблюдать | CVE-2024-8784Эксплойта нет | QDocs Smart School Management System Chat mynewuser sql injectionqdocs · smart school · CWE-89 | Средняя5,3 | — | 0,5 % | 13 сент. 2024 г. |
20Наблюдать | CVE-2025-41107Эксплойта нет | Stored XSS in Smart Schoolqdocs · smart school · CWE-79 | Средняя5,1 | — | 0,2 % | 10 нояб. 2025 г. |
19Наблюдать | CVE-2020-36011Эксплойта нет | A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbiqdocs · smart hospital · CWE-79 | Средняя4,8 | — | 0,7 % | 26 янв. 2021 г. |
- CVE-2023-549539Наблюдать
QDocs Smart School HTTP POST Request sql injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qdocs · smart school10 окт. 2023 г.
- CVE-2025-6050028Наблюдать
QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restricti
ВысокаяCVSS 7,2Proof of conceptEPSS 1 %qdocs · smart school21 окт. 2025 г.
- CVE-2024-3424024Наблюдать
QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin functions related to add
СредняяCVSS 6,1Эксплойта нетEPSS 0 %qdocs · smart school21 мая 2024 г.
- CVE-2024-878421Наблюдать
QDocs Smart School Management System Chat mynewuser sql injection
СредняяCVSS 5,3Эксплойта нетEPSS 1 %qdocs · smart school13 сент. 2024 г.
- CVE-2025-4110720Наблюдать
Stored XSS in Smart School
СредняяCVSS 5,1Эксплойта нетEPSS 0 %qdocs · smart school10 нояб. 2025 г.
- CVE-2020-3601119Наблюдать
A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbi
СредняяCVSS 4,8Эксплойта нетEPSS 1 %qdocs · smart hospital26 янв. 2021 г.