74cmsse

Vendor:

First CVE: May 26, 2022 · Active for 4 years

19
Total CVEs
More Total CVEs than 93% of tracked products
19.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact 74cmsse over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 26, 2022
4 years ago
Most Recent CVE
Oct 17, 2022
1,376 days ago

CVE Severity & Scoring

74cmsse19 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (52.6%)
Unknown0 (0.0%)
Required9 (47.4%)
Privileges Required
Low2 (10.5%)
High0 (0.0%)
None17 (89.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.
Oct 17, 20229.830NONO
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.
Jun 23, 20227.525NONO
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.
May 26, 20227.525NONO
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.
May 26, 20227.525NONO
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.
Jun 23, 20227.524NONO
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.
Jun 23, 20227.524NONO
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.
Jun 23, 20227.524NONO
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.
Jun 23, 20227.524NONO
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.
Jun 23, 20227.524NONO
74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Administrator account.
Oct 17, 20226.523NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For 74cmsse

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.5.1166.80.8%00
3.13.019.80.9%00
3.12.026.00.5%00