Vulnerabilities > Weaver

DATE CVE VULNERABILITY TITLE RISK
2024-01-20 CVE-2023-51892 Unspecified vulnerability in Weaver E-Cology 10.0.2310.01
An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.
network
low complexity
weaver
critical
9.8
2023-07-25 CVE-2023-34798 Unrestricted Upload of File with Dangerous Type vulnerability in Weaver E-Office
An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.
network
low complexity
weaver CWE-434
critical
9.8
2023-07-20 CVE-2023-3793 SQL Injection vulnerability in Weaver E-Cology 10.0.2310.01/9.0
A vulnerability was found in Weaver e-cology.
network
low complexity
weaver CWE-89
critical
9.8
2023-05-19 CVE-2023-2806 XXE vulnerability in Weaver E-Cology 9.0
A vulnerability classified as problematic was found in Weaver e-cology up to 9.0.
network
low complexity
weaver CWE-611
8.8
2023-05-17 CVE-2023-2765 Absolute Path Traversal vulnerability in Weaver Office Automation 9.5
A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic.
network
low complexity
weaver CWE-36
7.5
2023-05-17 CVE-2023-2766 Files or Directories Accessible to External Parties vulnerability in Weaver Office Automation 9.5
A vulnerability was found in Weaver OA 9.5 and classified as problematic.
network
low complexity
weaver CWE-552
7.5
2023-05-11 CVE-2023-2647 Command Injection vulnerability in Weaver E-Office 9.5
A vulnerability was found in Weaver E-Office 9.5 and classified as critical.
network
low complexity
weaver CWE-77
8.8
2023-05-11 CVE-2023-2648 Unrestricted Upload of File with Dangerous Type vulnerability in Weaver E-Office 9.5
A vulnerability was found in Weaver E-Office 9.5.
network
low complexity
weaver CWE-434
critical
9.8
2019-09-09 CVE-2019-16133 Insufficient Session Expiration vulnerability in Weaver Eteams OA 4.0.34
An issue was discovered in eteams OA v4.0.34.
network
low complexity
weaver CWE-613
4.0
2019-04-30 CVE-2019-10272 CRLF Injection vulnerability in Weaver E-Cology 9.0
An issue was discovered in Weaver e-cology 9.0.
network
weaver CWE-93
4.3