Qsoft Inc maintains a narrow product portfolio centered on search and analysis tools, specifically K-Rate and K-Search, that serve focused use cases within the vulnerability and threat-intelligence domain. The vendor's disclosed vulnerabilities remain limited in scope, and current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qsoft Inc over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-7097HIGH Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id variable in admin/includes/dele_cpac.php, (2 | Aug 27, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-3580HIGH Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the defa | Aug 10, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-7099MEDIUM Unspecified vulnerability in the Manage Templates feature in Qsoft K-Rate Premium allows remote attackers to execute arbitrary PHP code via unknown vectors. NOTE: the provenance o | Aug 27, 2009 | 6.8 | 27 | NO | YES |
CVE-2010-2457MEDIUM Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script or HTML via the term parameter. | Jun 25, 2010 | 4.3 | 22 | NO | YES |
CVE-2008-7098MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary web script or HTML via the blog, possibly the (1) Title and ( | Aug 27, 2009 | 4.3 | 21 | NO | YES |
CVE-2008-3581MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web script or HTML via the login_message parameter in a login act | Aug 10, 2008 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qsoft Inc.
Media articles that mention a CVE ID that affects a product developed by Qsoft Inc — matched by CVE ID, not by vendor name.