Easyflow .Net
Vendor:
First CVE: Aug 2, 2024 · Active for 1 year
5
Total CVEs
More Total CVEs than 79% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 66% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Easyflow .Net over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2024
23 months ago
Most Recent CVE
Jun 22, 2026
35 days ago
CVE Severity & Scoring
Easyflow .Net5 CVEs
40%
20%
40%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (80.0%)
High1 (20.0%)
Unknown0 (0.0%)
User Interaction
None3 (60.0%)
Unknown0 (0.0%)
Required2 (40.0%)
Privileges Required
Low2 (40.0%)
High0 (0.0%)
None3 (60.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5964CRITICAL EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete databas | Apr 20, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-5963CRITICAL EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete databas | Apr 20, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-12581HIGH EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's priv | Jun 22, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-12580MEDIUM EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' | Jun 22, 2026 | 5.4 | 25 | NO | NO |
CVE-2024-7323MEDIUM Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege ca | Aug 2, 2024 | 6.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Easyflow .Net
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.1.4 | 1 | 9.8 | 0.4% | 0 | 0 |
| 8.1.3 | 1 | 9.8 | 0.4% | 0 | 0 |
| 8.1.2 | 2 | 9.8 | 0.4% | 0 | 0 |
| 8.1.1 | 2 | 9.8 | 0.4% | 0 | 0 |
| 6.1.0 | 2 | 9.8 | 0.4% | 0 | 0 |