CVE-2026-102459
- EPSS 0.2%
- Veröffentlicht 30.09.2026 08:35:41
- Zuletzt bearbeitet 30.09.2026 16:30:42
EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.
CVE-2026-102458
- EPSS 0.43%
- Veröffentlicht 30.09.2026 08:34:09
- Zuletzt bearbeitet 30.09.2026 16:30:42
EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.
CVE-2026-102457
- EPSS 0.38%
- Veröffentlicht 30.09.2026 08:32:38
- Zuletzt bearbeitet 30.09.2026 16:30:42
EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.
CVE-2026-102456
- EPSS 0.27%
- Veröffentlicht 30.09.2026 08:30:47
- Zuletzt bearbeitet 30.09.2026 16:30:42
EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.
CVE-2026-102455
- EPSS 0.51%
- Veröffentlicht 30.09.2026 08:29:29
- Zuletzt bearbeitet 30.09.2026 16:30:42
EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
CVE-2026-102454
- EPSS 0.56%
- Veröffentlicht 30.09.2026 08:26:06
- Zuletzt bearbeitet 30.09.2026 16:30:42
EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
CVE-2026-12581
- EPSS 0.45%
- Veröffentlicht 22.06.2026 09:30:38
- Zuletzt bearbeitet 22.06.2026 20:17:59
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.
CVE-2026-12580
- EPSS 0.28%
- Veröffentlicht 22.06.2026 09:26:04
- Zuletzt bearbeitet 22.06.2026 20:17:59
EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.
CVE-2026-5964
- EPSS 0.37%
- Veröffentlicht 20.04.2026 07:36:58
- Zuletzt bearbeitet 12.05.2026 16:14:12
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-5963
- EPSS 0.37%
- Veröffentlicht 20.04.2026 07:32:20
- Zuletzt bearbeitet 12.05.2026 16:14:28
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.