newgensoft kayıtları
newgensoft üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-284 Improper Access Control1
- CWE-669 Incorrect Resource Transfer Between Spheres1
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
33İzleyin | CVE-2020-35737Kavram kanıtı | In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating thenewgensoft · egov | Yüksek7,5 | — | %10,4 | 30 Ara 2020 |
32İzleyin | CVE-2025-65742Kavram kanıtı | An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive innewgensoft · omnidocs · CWE-862 | Yüksek8,2 | — | %0,3 | 15 Ara 2025 |
31İzleyin | CVE-2011-3645Kavram kanıtı | Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jnewgensoft · omnidocs · CWE-264 | Yüksek7,5 | — | %2,6 | 27 Eyl 2011 |
31İzleyin | CVE-2018-17791İstismar yok | Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validnewgensoft · omniflow intelligent business process suite · CWE-669 | Yüksek7,5 | — | %1,9 | 21 Ağu 2019 |
30İzleyin | CVE-2010-0701Kavram kanıtı | SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commandsnewgensoft · omnidocs · CWE-89 | Yüksek7,5 | — | %1,2 | 23 Şub 2010 |
30İzleyin | CVE-2025-69908İstismar yok | An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a pubnewgensoft · omniapp · CWE-284 | Yüksek7,5 | — | %0,4 | 23 Oca 2026 |
- CVE-2020-3573733İzleyin
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the
YüksekCVSS 7,5Kavram kanıtıEPSS %10newgensoft · egov30 Ara 2020
- CVE-2025-6574232İzleyin
An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive in
YüksekCVSS 8,2Kavram kanıtıEPSS %0newgensoft · omnidocs15 Ara 2025
- CVE-2011-364531İzleyin
Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.j
YüksekCVSS 7,5Kavram kanıtıEPSS %3newgensoft · omnidocs27 Eyl 2011
- CVE-2018-1779131İzleyin
Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side valid
YüksekCVSS 7,5İstismar yokEPSS %2newgensoft · omniflow intelligent business process suite21 Ağu 2019
- CVE-2010-070130İzleyin
SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %1newgensoft · omnidocs23 Şub 2010
- CVE-2025-6990830İzleyin
An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a pub
YüksekCVSS 7,5İstismar yokEPSS %0newgensoft · omniapp23 Oca 2026