Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ragic

First CVE: Oct 31, 2022Active for: 4 yearsTotal CVEs: 7

Ragic operates a cloud-based database and application platform targeted at enterprise users, where its modest but visible vulnerability footprint concentrates on web application and data-access tiers. The recurring exposure centers on input-handling and authentication weaknesses—including cross-site scripting, path traversal, unrestricted file uploads, and missing authentication for critical functions—that are characteristic of database-as-a-service platforms where user input flows directly into data storage and retrieval workflows. Vulnerabilities affecting this vendor skew strongly toward critical severity, reflecting the sensitivity of cloud database access and the direct path from application logic to business data; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ragic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 31, 2022
3 years ago
Most Recent CVE
Dec 22, 2025
215 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-15016CRITICAL
Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verifi
Dec 22, 20259.835NONO
CVE-2024-9985CRITICAL
Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary c
Oct 15, 20249.830NONO
CVE-2024-9984CRITICAL
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user'
Oct 15, 20249.830NONO
CVE-2025-15015HIGH
Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbit
Dec 22, 20257.525NONO
CVE-2024-9983HIGH
Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary
Oct 15, 20247.522NONO
CVE-2022-40739MEDIUM
Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript to perform XSS (Reflected Cross-
Oct 31, 20225.421NONO
CVE-2023-41343MEDIUM
Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to p
Nov 3, 20235.416NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
29%
29%
43%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None5 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ragic.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ragic — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ragic's Products

View all 1 CNAs →

Top CWEs