Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
315037.8%CRITICAL

Related CVEs

15
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2026-3826IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.CRITICAL9.340.5%Mar 11, 2026
CVE-2026-3825IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.MEDIUM5.116.2%Mar 11, 2026
CVE-2026-3824IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visiting malicious website.MEDIUM5.19.3%Mar 11, 2026
CVE-2026-1429Single Sign-On Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.MEDIUM4.812.2%Jan 26, 2026
CVE-2026-1428Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.HIGH8.766.1%Jan 26, 2026
CVE-2026-1427Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.HIGH8.766.6%Jan 26, 2026
CVE-2025-8914Organization Portal System developed by WellChoose has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.HIGH7.127.5%Aug 13, 2025
CVE-2025-8913Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.CRITICAL9.343.5%Aug 13, 2025
CVE-2025-8912Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.HIGH8.741.1%Aug 13, 2025
CVE-2025-8911Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.MEDIUM5.324.3%Aug 13, 2025
CVE-2025-8910Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.MEDIUM5.324.3%Aug 13, 2025
CVE-2025-8909Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.HIGH7.143.8%Aug 13, 2025
CVE-2024-10202Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.HIGH8.860.2%Oct 21, 2024
CVE-2024-10201Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells.HIGH8.843.3%Oct 21, 2024
CVE-2024-10200Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to download arbitrary files on the server.HIGH7.548.8%Oct 21, 2024