Magicinfo 9 Server

Vendor:

First CVE: Aug 12, 2024 · Active for 1 year

23
Total CVEs
More Total CVEs than 96% of tracked products
7.7
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
9.7
Avg CVSS
Higher Avg CVSS than 88% of tracked products
8.7%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Magicinfo 9 Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2024
23 months ago
Most Recent CVE
Feb 2, 2026
176 days ago

CVE Severity & Scoring

Magicinfo 9 Server23 CVEs
All CVEs353,240 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None22 (95.7%)
Unknown0 (0.0%)
Required1 (4.3%)
Privileges Required
Low2 (8.7%)
High0 (0.0%)
None21 (91.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system au
Aug 12, 20249.898YESYES
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system au
May 13, 20259.887YESYES
A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue a
Feb 2, 20269.832NONO
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.10
Jul 23, 20259.830NONO
Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Serv
Jul 23, 20259.830NONO
An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21
Feb 2, 20268.829NONO
Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.
Jul 23, 20259.829NONO
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.Thi
Jul 23, 20259.829NONO
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.10
Jul 23, 20258.828NONO
The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21
Feb 2, 20269.827NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
2 CVEs
8.7% of CVEs· 98th percentile
Metasploit
1 CVE
4.3% of CVEs· 97th percentile
Nuclei
2 CVEs
8.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CWEs

Versions

No cataloged versions.