Raonwiz produces a narrowly scoped line of document-handling and file-upload utilities, including products such as DEXT5, K-Upload, and K-Editor, that process user-supplied content in enterprise and web environments. Its vulnerability profile skews strongly toward critical-severity outcomes and recurs through weakness classes centered on input validation, code integrity, and command-injection risks that are characteristic of applications handling untrusted file input and execution contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Raonwiz over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19168CRITICAL Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download and execute remote arbitrary file by setting the arguments t | May 6, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-7814CRITICAL RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can use | Jul 10, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-7808CRITICAL In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloa | May 21, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-19169CRITICAL Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download arbitrary file by setting the arguments to the activex metho | May 6, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-7863HIGH A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a specially-crafted web page. This vulnerability is due to ins | Aug 5, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-19164HIGH dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remote files to be executed by setting the arguments to the activ | May 7, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-29157HIGH An issue in RAONWIZ K Editor v2018.0.0.10 allows attackers to perform a DLL hijacking attack when the service or system is restarted. | Jul 14, 2021 | 7.8 | 25 | NO | NO |
CVE-2020-7817HIGH MyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a vulnerability in downloading arbitrary files due to insuffi | Aug 6, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-7830HIGH RAONWIZ v2018.0.2.50 and earlier versions contains a vulnerability that could allow remote files to be downloaded by lack of validation. Vulnerabilities in downloading with Kupload | Sep 2, 2020 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Raonwiz.
Media articles that mention a CVE ID that affects a product developed by Raonwiz — matched by CVE ID, not by vendor name.