Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
26029.9%CRITICAL

Related CVEs

6
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2026-5964EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.CRITICAL9.328.4%Apr 20, 2026
CVE-2026-5963EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.CRITICAL9.328.4%Apr 20, 2026
CVE-2024-7323Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .MEDIUM6.544.2%Aug 2, 2024
CVE-2022-32458Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.HIGH7.5Jul 20, 2022
CVE-2022-32457Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.MEDIUM5.3Jul 20, 2022
CVE-2022-32456Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.CRITICAL9.8Jul 20, 2022