Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ahsay

First CVE: Jul 26, 2019Active for: 7 yearsTotal CVEs: 7

Ahsay develops a focused cloud backup and recovery platform that serves as a critical data-protection layer across enterprise and mid-market environments, and its vulnerability profile centers on a single product line with a marked tendency toward public exploit availability. The recurring weakness classes—XML external entity injection, unrestricted file uploads, path traversal, argument injection, and cross-site scripting—reflect the input-handling and file-management demands of a web-facing backup appliance and are characteristic of application-layer security gaps that attract tooling and proof-of-concept development. Defenders should treat this vendor's advisories as requiring prompt patching, particularly for internet-reachable deployments; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ahsay over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 2019
6 years ago
Most Recent CVE
Sep 21, 2022
1,402 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-10267HIGH
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can inse
Jul 26, 20198.883NOYES
CVE-2019-10266HIGH
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the con
Jul 26, 20197.540NOYES
CVE-2022-37027HIGH
Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject
Sep 21, 20227.235NONO
CVE-2019-10265HIGH
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. On the /cbs/system/ShowAdvanced.do "File Explorer" screen, it is possible to change the directory in the JavaSc
Jul 26, 20197.525NONO
CVE-2019-10264HIGH
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen has an Import Users option. This
Jul 26, 20197.223NONO
CVE-2020-5846HIGH
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in t
Jan 6, 20208.822NONO
CVE-2019-10263MEDIUM
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the attacker to retrie
Jul 26, 20196.120NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
86%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (85.7%)
Unknown0 (0.0%)
Required1 (14.3%)
Privileges Required
Low2 (28.6%)
High2 (28.6%)
None3 (42.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
14.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
28.6% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ahsay.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ahsay — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ahsay's Products

View all 1 CNAs →

Top CWEs