Factorfx develops inventory and asset-management software, with its exposure concentrated in the OCS Inventory and Open Computer Software Inventory Next Generation products. The recurring weakness classes involve application-layer input handling, particularly cross-site scripting and OS command injection vulnerabilities typical of web-facing administrative interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Factorfx over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14947HIGH OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_con | Jun 30, 2020 | 8.8 | 43 | NO | YES |
CVE-2021-46355MEDIUM OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the vulnerability, the attacker needs to manipulate the name of some device on your computer, such as a pr | Feb 11, 2022 | 5.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Factorfx.
Media articles that mention a CVE ID that affects a product developed by Factorfx — matched by CVE ID, not by vendor name.