Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Platform HIGH 7.8
CVE-2025-1683

Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivile…

Fix: 25.3+
Fix from $1,950 2025-03-12
Platform MEDIUM 6.1
CVE-2024-7211

The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attack…

Mitigation only
Fix from $1,600 2024-08-01
Platform HIGH 7.2
CVE-2023-5964

The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly valida…

Fix: 23.0+
Fix from $1,950 2023-11-06
Platform HIGH 7.2
CVE-2023-45161

The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL …

Fix: 20.1+
Fix from $1,950 2023-11-06
Platform HIGH 7.2
CVE-2023-45163

The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the inpu…

Fix: 18.1+
Fix from $1,950 2023-11-06
Platform CRITICAL 9.8
CVE-2023-45162

Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution.  Application of the relevant hotfi…

Mitigation only
Fix from $2,300 2023-10-13
Client HIGH 8.8
CVE-2023-45160

In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script.…

Mitigation only
Fix from $1,950 2023-10-05
Client HIGH 8.4
CVE-2023-45159

1E Client installer can perform arbitrary file deletion on protected files.   A non-privileged user could provide a symbolic link or Windows junctio…

Mitigation only
Fix from $1,950 2023-10-05
Client HIGH 8.8
CVE-2020-16268

The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair o…

Mitigation only
Fix from $1,950 2020-12-29
Client HIGH 8.8
CVE-2020-27644

The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.e…

Mitigation only
Fix from $1,950 2020-12-29
Client HIGH 8.8
CVE-2020-27645

The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.e…

Mitigation only
Fix from $1,950 2020-12-29
Client MEDIUM 6.5
CVE-2020-27643

The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify fil…

Mitigation only
Fix from $1,600 2020-12-29