Eginnovations develops a focused portfolio of infrastructure monitoring and management tools, including its EG Manager platform, Agent components, RUM collectors, and VM Agent, which collectively form an enterprise observability stack. Vulnerabilities documented against this vendor recur around authentication and access-control handling alongside SQL injection in query and data-processing layers, reflecting the authentication and database-integration demands of centralized monitoring architectures. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eginnovations over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8592CRITICAL eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature). | Feb 3, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-8591CRITICAL eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request. | Feb 3, 2020 | 9.8 | 29 | NO | NO |
CVE-2022-29594HIGH eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. | Jun 2, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eginnovations.
Media articles that mention a CVE ID that affects a product developed by Eginnovations — matched by CVE ID, not by vendor name.