bigantsoft CVE Vulnerabilities & Metrics

Focus on bigantsoft vulnerabilities and metrics.

Last updated: 25 Nov 2025, 23:25 UTC

About bigantsoft Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with bigantsoft. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total bigantsoft CVEs: 11
Earliest CVE date: 22 Apr 2008, 04:41 UTC
Latest CVE date: 04 Feb 2025, 18:15 UTC

Latest CVE reference: CVE-2025-0364

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical bigantsoft CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.67

Max CVSS: 10.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 9
7.0-8.9 1
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS bigantsoft CVEs

These are the five CVEs with the highest CVSS scores for bigantsoft, sorted by severity first and recency.

All CVEs for bigantsoft

CVE-2025-0364 bigantsoft vulnerability CVSS: 0 04 Feb 2025, 18:15 UTC

BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker can create an administrative user through the default exposed SaaS registration mechanism. Once an administrator, the attacker can upload and execute arbitrary PHP code using the "Cloud Storage Addin," leading to unauthenticated code execution.

CVE-2024-54761 bigantsoft vulnerability CVSS: 0 09 Jan 2025, 20:15 UTC

BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.

CVE-2021-43430 bigantsoft vulnerability CVSS: 6.5 07 Apr 2022, 18:15 UTC

An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files.

CVE-2022-26281 bigantsoft vulnerability CVSS: 5.0 05 Apr 2022, 02:15 UTC

BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.

CVE-2022-23352 bigantsoft vulnerability CVSS: 5.0 21 Mar 2022, 20:15 UTC

An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).

CVE-2022-23350 bigantsoft vulnerability CVSS: 3.5 21 Mar 2022, 20:15 UTC

BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2022-23349 bigantsoft vulnerability CVSS: 6.8 21 Mar 2022, 20:15 UTC

BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).

CVE-2022-23348 bigantsoft vulnerability CVSS: 5.0 21 Mar 2022, 20:15 UTC

BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.

CVE-2022-23347 bigantsoft vulnerability CVSS: 5.0 21 Mar 2022, 20:15 UTC

BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.

CVE-2022-23346 bigantsoft vulnerability CVSS: 6.5 21 Mar 2022, 20:15 UTC

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.

CVE-2022-23345 bigantsoft vulnerability CVSS: 5.0 21 Mar 2022, 20:15 UTC

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.

CVE-2012-6275 bigantsoft vulnerability CVSS: 10.0 24 Feb 2013, 11:48 UTC

Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request.

CVE-2012-6274 bigantsoft vulnerability CVSS: 5.0 24 Feb 2013, 11:48 UTC

BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.

CVE-2012-6273 bigantsoft vulnerability CVSS: 7.5 24 Feb 2013, 11:48 UTC

SQL injection vulnerability in BigAntSoft BigAnt IM Message Server allows remote attackers to execute arbitrary SQL commands via an SHU (aka search user) request.

CVE-2009-4660 bigantsoft vulnerability CVSS: 10.0 03 Mar 2010, 20:30 UTC

Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to execute arbitrary code via a long GET request to TCP port 6660.

CVE-2008-1914 bigantsoft vulnerability CVSS: 10.0 22 Apr 2008, 04:41 UTC

Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows remote attackers to execute arbitrary code via a long URI in a request to TCP port 6080. NOTE: some of these details are obtained from third party information.