Secureideas maintains a focused product portfolio centered on its Basic Analysis and Security Engine platform, a moderately prominent offering in the vulnerability landscape. The vendor's disclosures cluster around application-layer input-handling and authentication weaknesses, including cross-site scripting, SQL injection, code injection, and improper input validation, with a high tendency toward public exploit availability. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Secureideas over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1198HIGH base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents of the file with an executable extension | Feb 18, 2012 | 7.5 | 34 | NO | YES |
CVE-2012-1017HIGH Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary SQL commands via the (1) | Feb 8, 2012 | 7.5 | 34 | NO | YES |
CVE-2012-1199HIGH Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) BASE | Feb 18, 2012 | 7.5 | 33 | NO | YES |
CVE-2005-3325HIGH Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security | Oct 27, 2005 | 7.5 | 29 | NO | YES |
CVE-2007-5578HIGH Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication via (1) base_ma | Oct 18, 2007 | 7.5 | 20 | NO | NO |
CVE-2009-4838HIGH SQL injection vulnerability in base_ag_common.php in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allows remote attackers to execute arbitrary SQL commands via unspecif | May 6, 2010 | 7.5 | 19 | NO | NO |
CVE-2009-4592HIGH Unspecified vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to include arbitrary local files via unknown vec | Jan 7, 2010 | 7.5 | 19 | NO | NO |
CVE-2009-4591HIGH SQL injection vulnerability in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Jan 7, 2010 | 7.5 | 19 | NO | NO |
CVE-2009-4839MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote attackers to inject arbitrary web script | May 6, 2010 | 4.3 | 15 | NO | NO |
CVE-2009-4837MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allow remote attackers to inject arbitrary web script or HTML via th | May 6, 2010 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Secureideas.
Media articles that mention a CVE ID that affects a product developed by Secureideas — matched by CVE ID, not by vendor name.