Vulnerabilities
Vulnerable Software
Venki:  Security Vulnerabilities
An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on the underlying host system.
CVSS Score
8.4
EPSS Score
0.002
Published
2025-01-13
The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.
CVSS Score
7.2
EPSS Score
0.001
Published
2025-01-13
Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote code execution.
CVSS Score
9.9
EPSS Score
0.009
Published
2025-01-13
Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
CVSS Score
9.8
EPSS Score
0.026
Published
2020-07-07
A user enumeration vulnerability flaw was found in Venki Supravizio BPM 10.1.2. This issue occurs during password recovery, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames.
CVSS Score
5.3
EPSS Score
0.004
Published
2020-07-07


Contact Us

Shodan ® - All rights reserved