Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xplatform HIGH 8.8
CVE-2021-26629

A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompre…

Fix: 9.2.2.284+
Fix from $1,950 2022-04-26
Nexacro HIGH 8.8
CVE-2021-26625

Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caus…

Fix: 17.1.3.700+
Fix from $1,950 2022-04-19
Xplatform HIGH 8.8
CVE-2021-26626

Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the second parameter value of the …

Fix: 9.2.2.280+
Fix from $1,950 2022-04-19
Nexacro HIGH 7.5
CVE-2021-26613

improper input validation vulnerability in nexacro permits copying file to the startup folder using rename method.

Fix: 17.1.2.500+
Fix from $1,950 2022-02-09
Nexacro CRITICAL 9.8
CVE-2021-26612

An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method t…

Fix: after 17.1.2.500
Fix from $2,300 2021-11-30
Nexacro CRITICAL 9.8
CVE-2021-26607

An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems.

Fix: after 17.1.3.301
Fix from $2,300 2021-10-26
Nexacro HIGH 8.8
CVE-2020-7874

Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbi…

Fix: 14.0.1.3600+
Fix from $1,950 2021-09-09
Xplatform CRITICAL 9.8
CVE-2020-7866

When using XPLATFORM 9.2.2.270 or earlier versions ActiveX component, arbitrary commands can be executed due to improper input validation

Fix: after 9.2.2.270
Fix from $2,300 2021-07-20
Xplatform CRITICAL 9.8
CVE-2020-7857

A vulnerability of XPlatform could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient vali…

Fix: 9.2.2.280+
Fix from $2,300 2021-04-20
Xplatform CRITICAL 9.8
CVE-2020-7853

An outbound read/write vulnerability exists in XPLATFORM that does not check offset input ranges, allowing out-of-range data to be read. An attacker …

Fix: after 9.2.2.250
Fix from $2,300 2021-03-24
Xplatform HIGH 8.8
CVE-2020-7841

Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun…

Fix: 9.2.2.250+
Fix from $1,950 2020-11-17
Miplatform CRITICAL 9.8
CVE-2020-7825

A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker …

Fix: after 2019.05.16
Fix from $2,300 2020-07-17
Xplatform CRITICAL 9.8
CVE-2020-7815

XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulner…

Fix: after 9.2.2.260
Fix from $2,300 2020-07-10
Xplatform HIGH 7.8
CVE-2019-19162

A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system running it.

Fix: after 9.2.2
Fix from $1,950 2020-05-11
Xplatform CRITICAL 9.8
CVE-2020-7806

Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supported by Xplatform ActiveX Contro…

Fix: after 9.2.2.250
Fix from $2,300 2020-05-06
Nexacro CRITICAL 9.8
CVE-2019-19167

Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method supported by Nexacro14 ActiveX Contr…

Fix: after 2019.9.25.1
Fix from $2,300 2020-05-06
Xplatform HIGH 7.8
CVE-2019-19166

Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows attacker to cause remote code ex…

Mitigation only
Fix from $1,950 2020-05-06
Xplatform HIGH 7.8
CVE-2018-5197

A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command i…

Mitigation only
Fix from $1,950 2019-01-02