Ebmtech's vulnerability profile concentrates in a small set of web-based application and server products such as RisWeb and UniWeb/Solipacs WebServer, with the durable signal centered on input-handling and access-control weaknesses including SQL injection and missing authentication for critical functions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ebmtech over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-26264CRITICAL EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers t | Feb 15, 2024 | 9.8 | 24 | NO | NO |
CVE-2024-26262HIGH EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL comm | Feb 15, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-26263HIGH EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive data without login. | Feb 15, 2024 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ebmtech.
Media articles that mention a CVE ID that affects a product developed by Ebmtech — matched by CVE ID, not by vendor name.