Eve Ng is a network emulation and simulation platform used in enterprise training and lab environments, with a narrowly scoped product footprint centered on its core emulation software. The observed weakness classes in its disclosure history reflect typical application security concerns; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eve Ng over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27903HIGH An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attac | May 4, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-31366HIGH An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file | Oct 20, 2022 | 7.2 | 26 | NO | NO |
CVE-2025-67442HIGH EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export lab files. This interface lacks effective input validation | Dec 19, 2025 | 7.6 | 23 | NO | NO |
CVE-2024-2391MEDIUM A vulnerability was found in EVE-NG 5.0.1-13 and classified as problematic. Affected by this issue is some unknown functionality of the component Lab Handler. The manipulation lead | Mar 12, 2024 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eve Ng.
Media articles that mention a CVE ID that affects a product developed by Eve Ng — matched by CVE ID, not by vendor name.