VendorsVenkisupravizio_bpmany version
Vulnerabilities

Venki Supravizio BPM any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-46479
Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote code execution.
Published 2025-01-13 · Analyzed
9.9EPSS 0.008
CVE-2024-46480
An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on the underlying host system.
Published 2025-01-13 · Analyzed
8.4EPSS 0.005
CVE-2024-46481
The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.
Published 2025-01-13 · Analyzed
7.2EPSS 0.003