Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    4
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-36846

    An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. The endpoint takes an input parameter that is passed directly into the shell_exec() function of PHP. NOTE: this can be chained with CVE-2025-36845.

    Last Modified: Sep 12, 2025
    Published: Jul 21, 2025

    CVE-2025-36845

    An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only reachable by the application server.

    Last Modified: Sep 12, 2025
    Published: Jul 21, 2025

    CVE-2022-2420

    URVE Web Manager uploader.php unrestricted upload

    Last Modified: Apr 15, 2025
    Published: Jul 15, 2022

    CVE-2022-2419

    URVE Web Manager upload.php unrestricted upload

    Last Modified: Apr 15, 2025
    Published: Jul 15, 2022

    CVE-2022-2418

    URVE Web Manager img_upload.php unrestricted upload

    Last Modified: Apr 15, 2025
    Published: Jul 15, 2022
    Items Per Page
    Eveo Vulnerabilities & Security CVEs | CVE-DB