Douzone develops business-management and enterprise-resource-planning software, with observed vulnerabilities concentrating in products such as Neors and components like NBBDownloader.ocx. The durable signal centers on application-layer input-handling weaknesses, including improper input validation, argument injection, and origin validation errors that are characteristic of web-facing business applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Douzone over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7880HIGH The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because o | Nov 30, 2021 | 8.8 | 28 | NO | NO |
CVE-2022-23763HIGH Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage us | Jun 28, 2022 | 8.8 | 27 | NO | NO |
CVE-2020-7850HIGH NBBDownloader.ocx ActiveX Control in Groupware contains a vulnerability that could allow remote files to be downloaded and executed by setting the arguments to the activex method. | Mar 29, 2021 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Douzone.
Media articles that mention a CVE ID that affects a product developed by Douzone — matched by CVE ID, not by vendor name.