VYPR
Vendor

Gss

Products
4
CVEs
14
Across products
14
Status
Private

Products

4

Recent CVEs

14
  • CVE-2026-4639HigMar 24, 2026
    risk 0.57cvss 8.8epss 0.00

    Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform certain administrative functions, thereby escalating privileges.

  • CVE-2023-41357HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute…

  • CVE-2023-37291HigJul 21, 2023
    risk 0.56cvss 8.6epss 0.00

    Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP:…

  • CVE-2026-4640HigMar 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to execute certain functions to obtain sensitive information.

  • CVE-2024-52959HigNov 27, 2024
    risk 0.47cvss 7.2epss 0.01

    A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

  • CVE-2024-52958HigNov 27, 2024
    risk 0.47cvss 7.2epss 0.00

    A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.

  • CVE-2025-14255MedDec 8, 2025
    risk 0.42cvss 6.5epss 0.00

    Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

  • CVE-2025-14254MedDec 8, 2025
    risk 0.42cvss 6.5epss 0.00

    Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

  • CVE-2025-14253MedDec 8, 2025
    risk 0.32cvss 4.9epss 0.00

    Vitals ESP developed by Galaxy Software Services has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

  • CVE-2023-25567HigFeb 14, 2023
    risk 0.00cvss 7.5epss 0.01

    GSS-NTLMSSP, a mechglue plugin for the GSSAPI library that implements NTLM authentication, has an out-of-bounds read when decoding target information prior to version 1.2.0. The length of the `av_pair` is not checked properly for two of the elements which can trigger an…

  • CVE-2023-25566HigFeb 14, 2023
    risk 0.00cvss 7.5epss 0.01

    GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, a memory leak can be triggered when parsing usernames which can trigger a denial-of-service. The domain portion of a username may be overridden causing an…

  • CVE-2023-25565HigFeb 14, 2023
    risk 0.00cvss 7.5epss 0.01

    GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, an incorrect free when decoding target information can trigger a denial of service. The error condition incorrectly assumes the `cb` and `sh` buffers contain a…

  • CVE-2023-25564MedFeb 14, 2023
    risk 0.00cvss 6.5epss 0.02

    GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, memory corruption can be triggered when decoding UTF16 strings. The variable `outlen` was not initialized and could cause writing a zero to an arbitrary place in…

  • CVE-2023-25563MedFeb 14, 2023
    risk 0.00cvss 5.9epss 0.01

    GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, multiple out-of-bounds reads when decoding NTLM fields can trigger a denial of service. A 32-bit integer overflow condition can lead to incorrect checks of…