Descor provides a facility management and information platform, with vulnerabilities clustering around its InfoCAD product line. The exposure pattern centers on authentication and access-control weaknesses—including capture-replay attacks, improper authentication, SQL injection, and insufficient credential protection—that are characteristic of web-based administrative interfaces. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Descor over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-26852CRITICAL DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection. | Mar 20, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-26853CRITICAL DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema. | Mar 20, 2025 | 9.8 | 25 | NO | NO |
CVE-2018-13789HIGH An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers. | Oct 10, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Descor.
Media articles that mention a CVE ID that affects a product developed by Descor — matched by CVE ID, not by vendor name.