Tcexam

Vendor:

First CVE: Jun 3, 2010 · Active for 16 years

23
Total CVEs
More Total CVEs than 96% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tcexam over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2010
16 years ago
Most Recent CVE
Jan 11, 2024
928 days ago

CVE Severity & Scoring

Tcexam23 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network17 (73.9%)
Unknown6 (26.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (73.9%)
High0 (0.0%)
Unknown6 (26.1%)
User Interaction
None5 (21.7%)
Unknown6 (26.1%)
Required12 (52.2%)
Privileges Required
Low8 (34.8%)
High1 (4.3%)
None8 (34.8%)
Unknown6 (26.1%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database
Jul 30, 20217.537NOYES
Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploading
Jun 3, 20106.833NOYES
Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the subj
Aug 20, 20126.831NOYES
When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information l
Jan 11, 20246.521NONO
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validate
Aug 5, 20216.121NONO
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and
Aug 5, 20216.121NONO
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we
Jul 30, 20215.320NONO
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered a
Jul 30, 20215.420NONO
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as tex
Jul 30, 20215.420NONO
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.
Jul 7, 20186.120NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.3% of CVEs· 97th percentile
ExploitDB
2 CVEs
8.7% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Tcexam

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
14.2.295.60.9%00
11.3.00725.21.7%00
11.3.00644.81.7%01
11.3.00544.81.7%01
11.3.00444.81.7%01
11.3.00344.81.7%01
11.3.00244.81.7%01
11.3.00144.81.7%01
11.3.00044.81.7%01
11.2.03244.81.7%01
11.2.03144.81.7%01
11.2.03044.81.7%01
11.2.02944.81.7%01
11.2.02844.81.7%01
11.2.02744.81.7%01
11.2.02644.81.7%01
11.2.02544.81.7%01
11.2.02344.81.7%01
11.2.02244.81.7%01
11.2.02144.81.7%01