Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-80235 | 1 Thinkingsoftware | 1 Efence | 2026-08-28 | 9.8 Critical |
| EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | ||||
| CVE-2026-80236 | 1 Thinkingsoftware | 1 Efence | 2026-08-28 | 8.2 High |
| Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents. | ||||
| CVE-2026-80237 | 1 Thinkingsoftware | 1 Efence | 2026-08-28 | 8.8 High |
| EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | ||||
| CVE-2023-22900 | 1 Thinkingsoftware | 1 Efence | 2025-03-27 | 9.8 Critical |
| Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database. | ||||
| CVE-2023-32754 | 1 Thinkingsoftware | 1 Efence | 2024-12-12 | 9.8 Critical |
| Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database. | ||||
Page 1 of 1.