← Back

Vitalsesp

vitalsesp

Vendor: Gss • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gss
1Vitalsesp
Jun 17, 2026
Mar 24, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to execute certain functions to obtain sensitive information.
1Gss
1Vitalsesp
Jun 17, 2026
Mar 24, 2026
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform certain administrative functions, thereby escalating privileges.
1Gss
1Vitalsesp
Jun 17, 2026
Dec 8, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
1Gss
1Vitalsesp
Jun 17, 2026
Dec 8, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
1Gss
1Vitalsesp
Jun 17, 2026
Dec 8, 2025
6.9 MEDIUM· v4
4.9 MEDIUM· v3
N/A· v2
Vitals ESP developed by Galaxy Software Services has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbitrary system files.