VaethinkCVEs & Vulnerabilities
4 CVEs affecting Vaethink products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
4 CVEs→ All vendors
Most Affected Products
vaethink 4
CVE-2024-38971MEDIUM
vaeThink 1.0.2 is vulnerable to stored Cross Site Scripting (XSS) in the system backend.
9 Jul 2024
5.4
CVSS
CVE-2024-38970MEDIUM
vaeThink 1.0.2 is vulnerable to Information Disclosure via the system backend,access management administrator function.
9 Jul 2024
4.9
CVSS
CVE-2020-19302CRITICAL
An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php".
4 Aug 2021
9.8
CVSS
CVE-2020-19301CRITICAL
A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condition parameter.
4 Aug 2021
9.8
CVSS
← PrevPage 1 / 1Next →