ruvar ruvaroa CVE Vulnerabilities (26)

CVEs: 26 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting ruvar ruvaroa (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 120 of 26 CVEs
«« First « Prev Page 1 / 2 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-25533 Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write files to the server or execute arbitrary commands via crafted SQL statements. [email protected] 9.4 0.22% 2024-05-08 2025-04-17
CVE-2024-25532 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx. [email protected] 9.8 0.12% 2024-05-08 2025-04-17
CVE-2024-25528 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx. [email protected] 5.9 0.06% 2024-05-08 2025-04-17
CVE-2024-25531 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aspx. [email protected] 9.8 0.13% 2024-05-08 2025-04-17
CVE-2024-25530 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condiction.aspx. [email protected] 9.8 0.13% 2024-05-08 2025-04-17
CVE-2024-25529 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_show.aspx. [email protected] 9.8 0.41% 2024-05-08 2025-04-17
CVE-2024-25527 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx. [email protected] 9.4 0.09% 2024-05-08 2025-04-17
CVE-2024-25526 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /ProjectManage/pm_gatt_inc.aspx. [email protected] 8.1 0.07% 2024-05-08 2025-04-17
CVE-2024-25525 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx. [email protected] 9.8 0.07% 2024-05-08 2025-04-17
CVE-2024-25524 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPlanAttachDownLoad.aspx. [email protected] 9.4 0.05% 2024-05-08 2025-04-17
CVE-2024-25523 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx. [email protected] 9.8 0.07% 2024-05-08 2025-04-17
CVE-2024-25522 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at /WorkFlow/wf_work_form_save.aspx. [email protected] 9.4 0.07% 2024-05-08 2025-04-17
CVE-2024-25521 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_company.aspx. [email protected] 9.4 0.05% 2024-05-08 2025-04-17
CVE-2024-25520 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.aspx. [email protected] 9.8 0.07% 2024-05-08 2025-04-17
CVE-2024-25519 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx. [email protected] 9.8 0.07% 2024-05-08 2025-04-17
CVE-2024-25518 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /WorkFlow/wf_get_fields_approve.aspx. [email protected] 9.4 0.05% 2024-05-08 2025-04-17
CVE-2024-25517 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx. [email protected] 9.8 0.07% 2024-05-08 2025-04-17
CVE-2024-25515 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_work_finish_file_down.aspx. [email protected] 7.3 0.06% 2024-05-08 2025-04-16
CVE-2024-25514 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysManage/wf_template_child_field_list.aspx. [email protected] 9.4 0.11% 2024-05-07 2025-04-16
CVE-2024-25513 RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_download.aspx. [email protected] 7.8 0.07% 2024-05-07 2025-04-16
«« First « Prev Page 1 / 2 Next »
cvelogic Threat Intelligence