Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ruvar

First CVE: May 7, 2024Active for: 2 yearsTotal CVEs: 26
56.4
VTI Score
TOP TARGET

Ruvar maintains a focused product portfolio centered on the RuvarOA application, which despite a narrow scope occupies a more prominent position in the vulnerability landscape than its product count might suggest. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, reflecting the severity of SQL-injection flaws in database-connected applications where input validation failures can lead to complete data compromise or system takeover. The recurring weakness class—improper neutralization of special elements in SQL commands—indicates a durable pattern of insufficient input sanitization that defenders should treat as a high-priority signal whenever this vendor's advisories are released. Organizations deploying RuvarOA should maintain aggressive patching discipline given the critical nature of the typical exposure; current exploitation activity, KEV status, and detailed severity counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
26.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
9.2
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ruvar over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 7, 2024
2 years ago
Most Recent CVE
May 8, 2024
807 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-25529CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_show.aspx.
May 8, 20249.829NONO
CVE-2024-25520CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.aspx.
May 8, 20249.829NONO
CVE-2024-25507CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /LHMail/AttachDown.aspx.
May 7, 20249.428NONO
CVE-2024-25519CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.
May 8, 20249.827NONO
CVE-2024-25532CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.
May 8, 20249.826NONO
CVE-2024-25525CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx.
May 8, 20249.826NONO
CVE-2024-25523CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.
May 8, 20249.826NONO
CVE-2024-25522CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at /WorkFlow/wf_work_form_save.aspx.
May 8, 20249.426NONO
CVE-2024-25517CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.
May 8, 20249.826NONO
CVE-2024-25533CRITICAL
Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to wri
May 8, 20249.425NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
15%
81%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (7.7%)
Network24 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (92.3%)
High2 (7.7%)
Unknown0 (0.0%)
User Interaction
None25 (96.2%)
Unknown0 (0.0%)
Required1 (3.8%)
Privileges Required
Low2 (7.7%)
High0 (0.0%)
None24 (92.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ruvar.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ruvar — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ruvar's Products

View all 1 CNAs →

Top CWEs