gss records
9 published records for vendor gss.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-321 Use of Hard-coded Cryptographic Key1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-36 Absolute Path Traversal1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-37291No exploit | Galaxy Software Services Vitals ESP - Use of Hard-coded Cryptographic Keygss · vitals enterprise social platform · CWE-321 | Critical9.8 | — | 0.5% | Jul 21, 2023 |
37Monitor | CVE-2024-52959No exploit | iota C.ai Conversational Platform - Improper Control of Generation of Code ('Code Injection')gss · iota c.ai · CWE-94 | Critical9.3 | — | 0.6% | Nov 27, 2024 |
37Monitor | CVE-2024-52958No exploit | iota C.ai Conversational Platform - Improper Verification of Cryptographic Signaturegss · iota c.ai · CWE-347 | Critical9.3 | — | 0.3% | Nov 27, 2024 |
35Monitor | CVE-2023-41357No exploit | Galaxy Software Services Vitals ESP - Arbitrary File Uploadgss · vitals enterprise social platform · CWE-434 | High8.8 | — | 0.6% | Nov 3, 2023 |
34Monitor | CVE-2026-4640No exploit | Galaxy Software Services|Vitals ESP - Missing Authenticationgss · vitalsesp · CWE-306 | High8.7 | — | 0.7% | Mar 24, 2026 |
34Monitor | CVE-2026-4639No exploit | Galaxy Software Services|Vitals ESP - Incorrect Authorizationgss · vitalsesp · CWE-863 | High8.7 | — | 0.5% | Mar 24, 2026 |
28Monitor | CVE-2025-14254No exploit | Galaxy Software Services|Vitals ESP - SQL Injectiongss · vitalsesp · CWE-89 | High7.1 | — | 0.3% | Dec 8, 2025 |
28Monitor | CVE-2025-14255No exploit | Galaxy Software Services|Vitals ESP - SQL Injectiongss · vitalsesp · CWE-89 | High7.1 | — | 0.3% | Dec 8, 2025 |
27Monitor | CVE-2025-14253No exploit | Galaxy Software Services|Vitals ESP - Arbitrary File Readgss · vitalsesp · CWE-36 | Medium6.9 | — | 0.5% | Dec 8, 2025 |
- CVE-2023-3729139Monitor
Galaxy Software Services Vitals ESP - Use of Hard-coded Cryptographic Key
CriticalCVSS 9.8No exploitEPSS 0%gss · vitals enterprise social platformJul 21, 2023
- CVE-2024-5295937Monitor
iota C.ai Conversational Platform - Improper Control of Generation of Code ('Code Injection')
CriticalCVSS 9.3No exploitEPSS 1%gss · iota c.aiNov 27, 2024
- CVE-2024-5295837Monitor
iota C.ai Conversational Platform - Improper Verification of Cryptographic Signature
CriticalCVSS 9.3No exploitEPSS 0%gss · iota c.aiNov 27, 2024
- CVE-2023-4135735Monitor
Galaxy Software Services Vitals ESP - Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%gss · vitals enterprise social platformNov 3, 2023
- CVE-2026-464034Monitor
Galaxy Software Services|Vitals ESP - Missing Authentication
HighCVSS 8.7No exploitEPSS 1%gss · vitalsespMar 24, 2026
- CVE-2026-463934Monitor
Galaxy Software Services|Vitals ESP - Incorrect Authorization
HighCVSS 8.7No exploitEPSS 1%gss · vitalsespMar 24, 2026
- CVE-2025-1425428Monitor
Galaxy Software Services|Vitals ESP - SQL Injection
HighCVSS 7.1No exploitEPSS 0%gss · vitalsespDec 8, 2025
- CVE-2025-1425528Monitor
Galaxy Software Services|Vitals ESP - SQL Injection
HighCVSS 7.1No exploitEPSS 0%gss · vitalsespDec 8, 2025
- CVE-2025-1425327Monitor
Galaxy Software Services|Vitals ESP - Arbitrary File Read
MediumCVSS 6.9No exploitEPSS 0%gss · vitalsespDec 8, 2025