Ragic
Ragic Enterprise Cloud Database: vulnerabilidades y CVE
Ragic Enterprise Cloud Database tiene 10 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses6
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-87747 | Media (6.9) | 0.61% | — | 9 sept 2026 | The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files. |
| CVE-2026-15553 | Media (6.9) | 0.41% | — | 13 jul 2026 | Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available for users to download. |
| CVE-2026-15552 | Media (5.3) | 0.34% | — | 13 jul 2026 | Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load. |
| CVE-2025-15016 | Crítica (9.3) | 0.53% | — | 22 dic 2025 | Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information and log into the… |
| CVE-2025-15015 | Alta (8.7) | 0.61% | — | 22 dic 2025 | Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. |
| CVE-2025-11675 | Alta (8.6) | 0.58% | — | 13 oct 2025 | Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the… |
| CVE-2024-9985 | Crítica (9.8) | 0.65% | — | 15 oct 2024 | Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server. |
| CVE-2024-9984 | Crítica (9.8) | 0.57% | — | 15 oct 2024 | Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie. |
| CVE-2024-9983 | Alta (7.5) | 0.67% | — | 15 oct 2024 | Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. |
| CVE-2023-41343 | Media (5.4) | 0.34% | — | 3 nov 2023 | Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.