VYPR
Vendor

FileWave

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2022-34907CriJul 25, 2022
    risk 0.65cvss 9.8epss 0.16

    An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.

  • CVE-2025-43922HigApr 21, 2025
    risk 0.53cvss 8.1epss 0.00

    The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.

  • CVE-2022-34906HigJul 25, 2022
    risk 0.50cvss 7.5epss 0.11

    A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.