Adminerevo is a database administration web interface with a modestly represented but above-typical vulnerability footprint, characterized by recurrent server-facing input and resource-handling weaknesses. The exposure clusters around path-traversal, server-side request forgery, uncontrolled resource consumption, and unrestricted file-upload vulnerabilities—flaws typical of web-based administrative tools that must parse user input and interact with backend systems. Current vulnerability counts, severity, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adminerevo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45197CRITICAL The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. The attacker can effectively gu | Jun 21, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-45196HIGH Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The | Jun 24, 2024 | 7.5 | 20 | NO | NO |
CVE-2023-45195MEDIUM Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would | Jun 24, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adminerevo.
Media articles that mention a CVE ID that affects a product developed by Adminerevo — matched by CVE ID, not by vendor name.