1E
First CVE: Oct 5, 2023Active for: 3 years
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
2.7
Avg CVEs / Year
More Avg CVEs / Year than 18% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by 1E as a CNA, 100.0% affect products that 1E develops as a vendor.
100.0%
Self-reported: 8Third-party: 0
Of all the CVEs published that affect products developed by 1E, 66.7% are self-published by 1E as a CNA.
66.7%
33.3%
Self-published: 8Published by other CNAs: 4
Trends Over Time
The number and severity of CVEs published by 1E over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2023
2 years ago
Most Recent CVE
Mar 12, 2025
499 days ago
Top CVEs
All CVEs published by 1E as a CNA, regardless of affected vendor or product.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45162CRITICAL Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution.
Application of the relevant hotfix remediates this issue.
for v | Oct 13, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-45163HIGH The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a | Nov 6, 2023 | 7.2 | 24 | NO | NO |
CVE-2023-45161HIGH The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a s | Nov 6, 2023 | 7.2 | 24 | NO | NO |
CVE-2023-45160HIGH In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script | Oct 5, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-5964HIGH The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly validate the Caption or Message param | Nov 6, 2023 | 7.2 | 23 | NO | NO |
CVE-2023-45159HIGH 1E Client installer can perform arbitrary file deletion on protected files.
A non-privileged user could provide a symbolic link or Windows junction to point to a protected direc | Oct 5, 2023 | 8.4 | 23 | NO | NO |
CVE-2025-1683HIGH Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system | Mar 12, 2025 | 7.8 | 21 | NO | NO |
CVE-2024-7211MEDIUM The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection p | Aug 1, 2024 | 6.1 | 18 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA8 CVEs
13%
75%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (25.0%)
Network6 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low2 (25.0%)
High3 (37.5%)
None3 (37.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by 1E as a CNA.
Media Mentions
Media articles that mention a CVE ID published by 1E as a CNA — matched by CVE ID, not by organization name.