Vulnerabilities > Kioware

DATE CVE VULNERABILITY TITLE RISK
2023-06-19 CVE-2023-34641 Unspecified vulnerability in Kioware
KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10.
local
low complexity
kioware
7.8
2023-06-19 CVE-2023-34642 Unspecified vulnerability in Kioware
KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10.
local
low complexity
kioware
7.8
2023-03-06 CVE-2022-44875 Cross-site Scripting vulnerability in Kioware
KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.
network
low complexity
kioware CWE-79
5.4
2019-03-21 CVE-2018-18435 Incorrect Permission Assignment for Critical Resource vulnerability in Kioware Server
KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full permission "Everyone: (F)" to the contents of the directory and it's sub-folders.
local
low complexity
kioware CWE-732
7.8