Vulnerabilities in DOS Co., Ltd.
11 resultsVexday analysis
A DOS Co., Ltd. apresenta 11 vulnerabilidades registradas, com 2 classificadas como críticas, predominantemente relacionadas a path traversal (CWE-22). Nenhuma vulnerabilidade está sob ataque ativo (KEV) e não houve publicações nos últimos 90 dias, indicando um panorama de risco estável e sem exploração imediata observada. O foco de remediação deve concentrar-se na validação de entrada em operações de arquivo e caminho, particularmente nas 2 vulnerabilidades críticas identificadas.
CVE-2023-22336—Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to EPSS 1.1%CVE-2023-22344—Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remoEPSS 0.9%CVE-2023-22335—Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attEPSS 0.7%CVE-2025-58072HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:EPSS 0.6%CVE-2025-53970CRITICALSS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and exeEPSS 0.5%CVE-2025-54762CRITICALSS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and exeEPSS 0.5%CVE-2025-54819HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:EPSS 0.5%CVE-2025-58081HIGHUse of hard-coded password issue/vulnerability in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenEPSS 0.4%CVE-2025-52460MEDIUMFiles or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If exEPSS 0.3%CVE-2025-46409HIGHInadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is eEPSS 0.2%CVE-2025-53396HIGHIncorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier), whiEPSS 0.1%