Tcexam
Vendor:
First CVE: Jun 3, 2010 · Active for 16 years
23
Total CVEs
More Total CVEs than 96% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tcexam over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2010
16 years ago
Most Recent CVE
Jan 11, 2024
928 days ago
CVE Severity & Scoring
Tcexam23 CVEs
87%
9%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network17 (73.9%)
Unknown6 (26.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (73.9%)
High0 (0.0%)
Unknown6 (26.1%)
User Interaction
None5 (21.7%)
Unknown6 (26.1%)
Required12 (52.2%)
Privileges Required
Low8 (34.8%)
High1 (4.3%)
None8 (34.8%)
Unknown6 (26.1%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20114HIGH When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database | Jul 30, 2021 | 7.5 | 37 | NO | YES |
CVE-2010-2153MEDIUM Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploading | Jun 3, 2010 | 6.8 | 33 | NO | YES |
CVE-2012-4237MEDIUM Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the subj | Aug 20, 2012 | 6.8 | 31 | NO | YES |
CVE-2023-6554MEDIUM When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information l | Jan 11, 2024 | 6.5 | 21 | NO | NO |
CVE-2021-20116MEDIUM A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validate | Aug 5, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-20115MEDIUM A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and | Aug 5, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-20113MEDIUM An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we | Jul 30, 2021 | 5.3 | 20 | NO | NO |
CVE-2021-20112MEDIUM A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered a | Jul 30, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-20111MEDIUM A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as tex | Jul 30, 2021 | 5.4 | 20 | NO | NO |
CVE-2018-13422MEDIUM TCExam before 14.1.2 has XSS via an ff_ or xl_ field. | Jul 7, 2018 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.3% of CVEs· 97th percentile
ExploitDB
2 CVEs
8.7% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Tcexam
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 14.2.2 | 9 | 5.6 | 0.9% | 0 | 0 |
| 11.3.007 | 2 | 5.2 | 1.7% | 0 | 0 |
| 11.3.006 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.3.005 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.3.004 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.3.003 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.3.002 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.3.001 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.3.000 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.2.032 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.2.031 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.2.030 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.2.029 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.2.028 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.2.027 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.2.026 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.2.025 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.2.023 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.2.022 | 4 | 4.8 | 1.7% | 0 | 1 |
| 11.2.021 | 4 | 4.8 | 1.7% | 0 | 1 |