Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

E Cology CRITICAL 9.8
CVE-2026-22679EPSS 21%

Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/dev…

Fix: 20260312+
Fix from $2,300 2026-04-07
E Cology HIGH 7.5
CVE-2025-34038

A SQL injection vulnerability exists in Weaver E-cology 8.0 via the getdata.jsp endpoint. The application directly passes unsanitized user input from…

Fix: after 8.0
Fix from $1,950 2025-06-24
E Cology CRITICAL 9.8
CVE-2024-48069

A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files and control…

Mitigation only
Fix from $2,300 2024-11-19
E Cology CRITICAL 9.8
CVE-2024-48070

An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and cont…

Mitigation only
Fix from $2,300 2024-11-19
E Cology CRITICAL 9.8
CVE-2024-48072

Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mob…

Mitigation only
Fix from $2,300 2024-11-19
E Cology MEDIUM 6.5
CVE-2024-48071

E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server directory, causing the server to pe…

Mitigation only
Fix from $1,600 2024-11-19
E Cology HIGH 7.5
CVE-2024-7704

A vulnerability was found in Weaver e-cology 8. It has been classified as problematic. Affected is an unknown function of the file /cloudstore/ecode/…

No fix yet
Fix from $1,950 2024-08-12
E Office HIGH 7.2
CVE-2024-3227

A vulnerability was found in Panwei eoffice OA up to 9.5. It has been declared as critical. This vulnerability affects unknown code of the file /gene…

Fix: after 9.5
Fix from $1,950 2024-04-03
E Cology CRITICAL 9.8
CVE-2023-51892

An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController co…

Mitigation only
Fix from $2,300 2024-01-20
E Office CRITICAL 9.8
CVE-2023-34798

An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.

Fix: 9.5+
Fix from $2,300 2023-07-25
E Cology CRITICAL 9.8
CVE-2023-3793

A vulnerability was found in Weaver e-cology. It has been rated as critical. This issue affects some unknown processing of the file filelFileDownload…

Fix: 10.58.0+
Fix from $2,300 2023-07-20
E Cology HIGH 8.8
CVE-2023-2806

A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of …

No fix yet
Fix from $1,950 2023-05-19
E Office HIGH 7.5
CVE-2023-2765

A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/Ap…

No fix yet
Fix from $1,950 2023-05-17
E Office HIGH 7.5
CVE-2023-2766EPSS 54%

A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/ur…

No fix yet
Fix from $1,950 2023-05-17
E Office CRITICAL 9.8
CVE-2023-2648EPSS 28%

A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/…

No fix yet
Fix from $2,300 2023-05-11
E Office HIGH 8.8
CVE-2023-2647EPSS 7%

A vulnerability was found in Weaver E-Office 9.5 and classified as critical. Affected by this issue is some unknown functionality of the file /webroo…

No fix yet
Fix from $1,950 2023-05-11
Eteams Oa MEDIUM 6.5
CVE-2019-16133

An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the co…

No fix yet
Fix from $1,600 2019-09-09
E Cology MEDIUM 6.1
CVE-2019-10272

An issue was discovered in Weaver e-cology 9.0. There is a CRLF Injection vulnerability via the /workflow/request/ViewRequestForwardSPA.jsp isinterve…

No fix yet
Fix from $1,600 2019-04-30