Nuserp develops an enterprise resource planning platform, the NUS-M9 ERP product, with a durable signal centered on application-layer code and command injection vulnerabilities alongside SQL injection weaknesses typical of data-driven business software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nuserp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-44756CRITICAL NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin. | Nov 18, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-44758CRITICAL An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading cra | Nov 15, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-44757HIGH An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access s | Nov 18, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-44759HIGH An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensiti | Nov 15, 2024 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nuserp.
Media articles that mention a CVE ID that affects a product developed by Nuserp — matched by CVE ID, not by vendor name.