Skip to main content

Vendor archive

venki CVEs

Beta · best-effort

5 CVEs tagged to vendor venki2 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-46481

Published Jan 13, 2025

The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46480

Published Jan 13, 2025

An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on the underlying host system.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46479

Published Jan 13, 2025

Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote code…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15392

Published Jul 7, 2020

A user enumeration vulnerability flaw was found in Venki Supravizio BPM 10.1.2. This issue occurs during password recovery, where a difference in error messages could allow an att…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15367

Published Jul 7, 2020

Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication att…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1