Solarview Compact
Vendor:
First CVE: Nov 17, 2022 · Active for 3 years
7
Total CVEs
More Total CVEs than 83% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 82% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Solarview Compact over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2022
3 years ago
Most Recent CVE
Oct 27, 2023
1,002 days ago
CVE Severity & Scoring
Solarview Compact7 CVEs
14%
14%
71%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (85.7%)
Unknown0 (0.0%)
Required1 (14.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23333CRITICAL There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. | Feb 6, 2023 | 9.8 | 94 | NO | YES |
CVE-2023-29919CRITICAL SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted. | May 23, 2023 | 9.1 | 66 | NO | YES |
CVE-2022-40881CRITICAL SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php | Nov 17, 2022 | 9.8 | 57 | NO | YES |
CVE-2023-40924HIGH SolarView Compact < 6.00 is vulnerable to Directory Traversal. | Sep 8, 2023 | 7.5 | 33 | NO | YES |
CVE-2022-44354CRITICAL SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. | Nov 29, 2022 | 9.8 | 32 | NO | NO |
CVE-2023-46509CRITICAL An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component. | Oct 27, 2023 | 9.8 | 25 | NO | NO |
CVE-2022-44355MEDIUM SolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php. | Nov 29, 2022 | 6.1 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
14.3% of CVEs· 97th percentile
Nuclei
4 CVEs
57.1% of CVEs· 99th percentile
ExploitDB
1 CVE
14.3% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Solarview Compact
Top CWEs
Versions
No cataloged versions.