Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Midasolutions

First CVE: Jul 24, 2020Active for: 6 yearsTotal CVEs: 7

Midasolutions maintains the eFramework product, a narrowly scoped enterprise application whose vulnerability profile skews toward critical-severity outcomes and frequently acquires public exploit code. The recurring exposure centers on input-handling and access-control weaknesses—including cross-site scripting, OS command injection, SQL injection, path traversal, and improper authentication—that are characteristic of web application attack surfaces and reflect gaps in input sanitization and privilege enforcement. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
7.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Midasolutions over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 24, 2020
5 years ago
Most Recent CVE
Jul 24, 2020
2,191 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-15920CRITICAL
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentic
Jul 24, 20209.894NOYES
CVE-2020-15922CRITICAL
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is re
Jul 24, 20209.873NOYES
CVE-2020-15921CRITICAL
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.
Jul 24, 20209.843NOYES
CVE-2020-15923HIGH
Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
Jul 24, 20207.525NONO
CVE-2020-15919MEDIUM
A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.
Jul 24, 20206.122NONO
CVE-2020-15924HIGH
There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authenticat
Jul 24, 20207.520NONO
CVE-2020-15918MEDIUM
Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.
Jul 24, 20205.420NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
29%
29%
43%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None6 (85.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
14.3% of CVEs· 98th percentile
Nuclei
1 CVE
14.3% of CVEs· 97th percentile
ExploitDB
3 CVEs
42.9% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Midasolutions.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Midasolutions — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Midasolutions's Products

View all 1 CNAs →

Top CWEs