Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Duware

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 23
50.0
VTI Score
TOP TARGET

Duware's vulnerability profile spans a modest portfolio of web application and directory-service products including DuClassified, DuPayPal, DuClassmate, DuDirectory, and DuDownload, each representing a point of potential exposure for organizations deploying this vendor's software. The most durable signal in this vendor's disclosures is the recurrence of SQL injection and related input-validation weaknesses, which are characteristic of web-facing application tiers where untrusted data flows directly into database queries. Notably, vulnerabilities affecting this vendor have frequently acquired public exploit code, making them attractive targets for routine scanning and mass-exploitation campaigns; organizations running these products should prioritize timely patching to reduce the window for weaponized access. The vendor's exposure is concentrated enough that defenders can track releases by product line, though the breadth of the affected application suite means vulnerabilities may propagate across multiple services within a single deployment. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Duware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Jun 26, 2008
6,603 days ago

Products(18 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-6355HIGH
SQL injection vulnerability in default.asp in DuWare DuClassmate allows remote attackers to execute arbitrary SQL commands via the iCity parameter. NOTE: the iState parameter is a
Dec 7, 200610.035NOYES
CVE-2004-2198MEDIUM
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" pag
Dec 31, 20046.433NOYES
CVE-2005-1224HIGH
Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parameter to default.asp, cat.asp, o
May 2, 20057.529NOYES
CVE-2008-2868HIGH
SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the iEve parameter.
Jun 26, 20087.528NOYES
CVE-2006-6365HIGH
SQL injection vulnerability in detail.asp in DUware DUpaypal 3.1, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: th
Dec 7, 20067.528NOYES
CVE-2006-6367HIGH
Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (
Dec 7, 20067.528NOYES
CVE-2005-2046HIGH
Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub p
Jun 22, 20057.528NOYES
CVE-2005-2048HIGH
Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to me
Jun 22, 20057.528NOYES
CVE-2005-2049HIGH
Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro pa
Jun 22, 20057.528NOYES
CVE-2005-1236HIGH
Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to channel.asp
May 2, 20057.528NOYES
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
26%
74%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown23 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown23 (100.0%)
User Interaction
None0 (0.0%)
Unknown23 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown23 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
14 CVEs
60.9% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Duware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Duware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Duware's Products

View all 1 CNAs →

Top CWEs