Platform
1E · 6 CVEs
CVE-2025-1683
HIGH
Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion
Mar 12, 2025
CVE-2024-7211
MEDIUM
The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.
Aug 1, 2024
CVE-2023-5964
CRITICAL
1E-Exchange-DisplayMessage instruction allows for arbitrary code execution
Nov 6, 2023
CVE-2023-45163
CRITICAL
1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution
Nov 6, 2023
CVE-2023-45161
CRITICAL
1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution
Nov 6, 2023
CVE-2023-45162
CRITICAL
Blind SQL vulnerability in 1E platform
Oct 13, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-1683 | Symbolic Link Exploit in 1E Client's - Nomad module allows Arbitrary File Deletion | HIGH | 0.22% | Mar 12, 2025 |
| CVE-2024-7211 | The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites. | MEDIUM | 0.24% | Aug 1, 2024 |
| CVE-2023-5964 | 1E-Exchange-DisplayMessage instruction allows for arbitrary code execution | CRITICAL | 0.83% | Nov 6, 2023 |
| CVE-2023-45163 | 1E-Exchange-CommandLinePing instruction before v18.1 allows for arbitrary code execution | CRITICAL | 0.86% | Nov 6, 2023 |
| CVE-2023-45161 | 1E-Exchange-URLResponseTime instruction before v20.1 allows arbitrary code execution | CRITICAL | 0.83% | Nov 6, 2023 |
| CVE-2023-45162 | Blind SQL vulnerability in 1E platform | CRITICAL | 0.64% | Oct 13, 2023 |
Showing 1 to 6 of 6 CVEs