← Back

Gss

gss

9 CVEs • 3 products

Products (3)

Click to collapse
Toggle

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gss
1Vitalsesp
Jun 17, 2026
Mar 24, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to execute certain functions to obtain sensitive information.
1Gss
1Vitalsesp
Jun 17, 2026
Mar 24, 2026
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform certain administrative functions, thereby escalating privileges.
1Gss
1Vitalsesp
Jun 17, 2026
Dec 8, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
1Gss
1Vitalsesp
Jun 17, 2026
Dec 8, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
1Gss
1Vitalsesp
Jun 17, 2026
Dec 8, 2025
6.9 MEDIUM· v4
4.9 MEDIUM· v3
N/A· v2
Vitals ESP developed by Galaxy Software Services has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
1Gss
1Iota C.ai
Jun 17, 2026
Nov 27, 2024
9.3 CRITICAL· v4
7.2 HIGH· v3
N/A· v2
A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system c...Show more
A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.Show less
1Gss
1Iota C.ai
Jun 17, 2026
Nov 27, 2024
9.3 CRITICAL· v4
7.2 HIGH· v3
N/A· v2
A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plu...Show more
A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.Show less
1Gss
1Vitals Enterprise Social Platform
Jun 17, 2026
Nov 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege...Show more
Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operations or disrupt service.Show less
1Gss
1Vitals Enterprise Social Platform
Jun 17, 2026
Jul 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate p...Show more
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0.Show less