1E kayıtları
1e üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %41,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-20 Improper Input Validation3
- CWE-428 Unquoted Search Path or Element2
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-45162İstismar yok | Blind SQL vulnerability in 1E platform1e · platform · CWE-89 | Kritik9,8 | — | %0,6 | 13 Eki 2023 |
35İzleyin | CVE-2020-16268İstismar yok | The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the1e · client · CWE-74 | Yüksek8,8 | — | %1,3 | 29 Ara 2020 |
35İzleyin | CVE-2020-27645İstismar yok | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.1e · client · CWE-428 | Yüksek8,8 | — | %1,2 | 29 Ara 2020 |
35İzleyin | CVE-2020-27644İstismar yok | The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.1e · client · CWE-428 | Yüksek8,8 | — | %1,2 | 29 Ara 2020 |
35İzleyin | CVE-2023-45160İstismar yok | Elevated Temp Directory Execution in 1E Client1e · client · CWE-552 | Yüksek8,8 | — | %0,7 | 5 Eki 2023 |
33İzleyin | CVE-2023-45159İstismar yok | 1E Client installer can perform arbitrary file deletion on protected files1e · client · CWE-59 | Yüksek8,4 | — | %0,2 | 5 Eki 2023 |
31İzleyin | CVE-2025-1683İstismar yok | Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion1e · platform · CWE-59 | Yüksek7,8 | — | %0,2 | 12 Mar 2025 |
28İzleyin | CVE-2023-45163İstismar yok | 1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution1e · platform · CWE-20 | Yüksek7,2 | — | %0,9 | 6 Kas 2023 |
28İzleyin | CVE-2023-45161İstismar yok | 1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution1e · platform · CWE-20 | Yüksek7,2 | — | %0,8 | 6 Kas 2023 |
28İzleyin | CVE-2023-5964İstismar yok | 1E-Exchange-DisplayMessage instruction allows for arbitrary code execution1e · platform · CWE-20 | Yüksek7,2 | — | %0,8 | 6 Kas 2023 |
26İzleyin | CVE-2020-27643İstismar yok | The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and m1e · client · CWE-59 | Orta6,5 | — | %1,4 | 29 Ara 2020 |
24İzleyin | CVE-2024-7211İstismar yok | The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.1e · platform · CWE-601 | Orta6,1 | — | %0,2 | 1 Ağu 2024 |
- CVE-2023-4516239İzleyin
Blind SQL vulnerability in 1E platform
KritikCVSS 9,8İstismar yokEPSS %11e · platform13 Eki 2023
- CVE-2020-1626835İzleyin
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the
YüksekCVSS 8,8İstismar yokEPSS %11e · client29 Ara 2020
- CVE-2020-2764535İzleyin
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.
YüksekCVSS 8,8İstismar yokEPSS %11e · client29 Ara 2020
- CVE-2020-2764435İzleyin
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.
YüksekCVSS 8,8İstismar yokEPSS %11e · client29 Ara 2020
- CVE-2023-4516035İzleyin
Elevated Temp Directory Execution in 1E Client
YüksekCVSS 8,8İstismar yokEPSS %11e · client5 Eki 2023
- CVE-2023-4515933İzleyin
1E Client installer can perform arbitrary file deletion on protected files
YüksekCVSS 8,4İstismar yokEPSS %01e · client5 Eki 2023
- CVE-2025-168331İzleyin
Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion
YüksekCVSS 7,8İstismar yokEPSS %01e · platform12 Mar 2025
- CVE-2023-4516328İzleyin
1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution
YüksekCVSS 7,2İstismar yokEPSS %11e · platform6 Kas 2023
- CVE-2023-4516128İzleyin
1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution
YüksekCVSS 7,2İstismar yokEPSS %11e · platform6 Kas 2023
- CVE-2023-596428İzleyin
1E-Exchange-DisplayMessage instruction allows for arbitrary code execution
YüksekCVSS 7,2İstismar yokEPSS %11e · platform6 Kas 2023
- CVE-2020-2764326İzleyin
The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and m
OrtaCVSS 6,5İstismar yokEPSS %11e · client29 Ara 2020
- CVE-2024-721124İzleyin
The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.
OrtaCVSS 6,1İstismar yokEPSS %01e · platform1 Ağu 2024