Vulnerabilities (CVE)

Filtered by vendor Digiwin Subscribe
Filtered by product Easyflow .net
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-5963 1 Digiwin 1 Easyflow .net 2026-05-12 N/A 9.8 CRITICAL
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-5964 1 Digiwin 1 Easyflow .net 2026-05-12 N/A 9.8 CRITICAL
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2024-7323 1 Digiwin 1 Easyflow .net 2024-09-11 N/A 6.5 MEDIUM
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server .