Eveo maintains a narrowly scoped web-management product, Urve Web Manager, whose vulnerability exposure centers on file-handling and command-execution flaws spanning unrestricted file uploads, OS command injection, and server-side request forgery. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eveo over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-36845HIGH An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, | Jul 21, 2025 | 8.6 | 34 | NO | YES |
CVE-2022-2419HIGH A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collector/upload.php. The manipulatio | Jul 15, 2022 | 8.0 | 32 | NO | NO |
CVE-2025-36846CRITICAL An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS C | Jul 21, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-2418HIGH A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.php. The manipulation leads to | Jul 15, 2022 | 8.0 | 26 | NO | NO |
CVE-2022-2420HIGH A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/uploader.php. The manipulation leads | Jul 15, 2022 | 8.0 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eveo.
Media articles that mention a CVE ID that affects a product developed by Eveo — matched by CVE ID, not by vendor name.