Urve maintains a focused product line centered on its core platform, with its vulnerability surface characterized by data-protection and command-execution weaknesses including cleartext storage of sensitive information, OS command injection, and missing authentication controls. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Urve over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-29551CRITICAL An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are | Dec 23, 2020 | 9.1 | 28 | NO | NO |
CVE-2020-29552CRITICAL An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring, it is possible to execute a Po | Dec 23, 2020 | 9.8 | 26 | NO | NO |
CVE-2020-29550HIGH An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in cleart | Dec 23, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Urve.
Media articles that mention a CVE ID that affects a product developed by Urve — matched by CVE ID, not by vendor name.