opexustech records
21 published records for vendor opexustech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-863 Incorrect Authorization2
- CWE-639 Authorization Bypass Through User-Controlled Key2
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-472 External Control of Assumed-Immutable Web Parameter1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2025-58462No exploit | OPEXUS FOIAXpress PAL SQL injectionopexustech · foiaxpress public access link · CWE-89 | Critical9.3 | — | 0.7% | Sep 9, 2025 |
37Monitor | CVE-2026-22234No exploit | OPEXUS eCasePortal unauthenticated IDORopexustech · ecase portal · CWE-639 | Critical9.3 | — | 0.4% | Jan 8, 2026 |
36Monitor | CVE-2024-53553No exploit | An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.opexustech · foiaxpress public access link · CWE-863 | Critical9.1 | — | 0.6% | Jan 16, 2025 |
36Monitor | CVE-2026-32865No exploit | OPEXUS eComplaint and eCase insecure password resetopexustech · ecase ecomplaint · CWE-200 | Critical9.2 | — | 0.5% | Mar 19, 2026 |
35Monitor | CVE-2025-62586No exploit | OPEXUS FOIAXpress unauthenticated administrator password resetopexustech · foiaxpress · CWE-306 | High8.9 | — | 0.7% | Oct 16, 2025 |
34Monitor | CVE-2026-22235No exploit | OPEXUS eComplaint IDORopexustech · ecase ecomplaint · CWE-639 | High8.7 | — | 0.4% | Jan 8, 2026 |
28Monitor | CVE-2026-22230No exploit | OPEXUS eCASE Audit incorrect access controlopexustech · ecase audit · CWE-863 | High7.2 | — | 0.3% | Jan 8, 2026 |
27Monitor | CVE-2025-54833No exploit | OPEXUS FOIAXpress Public Access Link (PAL) account-lockout and CAPTCHA protection bypassopexustech · foiaxpress public access link · CWE-307 | Medium6.9 | — | 0.5% | Jul 31, 2025 |
27Monitor | CVE-2025-54834No exploit | OPEXUS FOIAXpress Public Access Link (PAL) unauthenticated username enumerationopexustech · foiaxpress public access link · CWE-204 | Medium6.9 | — | 0.5% | Jul 31, 2025 |
21Monitor | CVE-2026-32867No exploit | OPEXUS eComplaint unauthenticated file uploadopexustech · ecase ecomplaint · CWE-425 | Medium5.3 | — | 0.4% | Mar 19, 2026 |
21Monitor | CVE-2025-54832No exploit | OPEXUS FOIAXpress Public Access Link (PAL) state and territory list unauthorized modificationopexustech · foiaxpress public access link · CWE-472 | Medium5.3 | — | 0.3% | Jul 31, 2025 |
20Monitor | CVE-2026-32869No exploit | OPEXUS eComplaint and eCASE XSS via Name of Organization fieldopexustech · ecase ecomplaint · CWE-79 | Medium5.1 | — | 0.2% | Mar 19, 2026 |
20Monitor | CVE-2026-32866No exploit | OPEXUS eComplaint and eCase stored XSS via profile first and last nameopexustech · ecase ecomplaint · CWE-79 | Medium5.1 | — | 0.2% | Mar 19, 2026 |
20Monitor | CVE-2026-32868No exploit | OPEXUS eComplaint and eCASE XSS via my informationopexustech · ecase ecomplaint · CWE-79 | Medium5.1 | — | 0.2% | Mar 19, 2026 |
19Monitor | CVE-2025-61998No exploit | OPEXUS FOIAXpress stored XSS via Hyperlink Manageropexustech · foiaxpress · CWE-79 | Medium4.8 | — | 0.2% | Oct 7, 2025 |
19Monitor | CVE-2025-61996No exploit | OPEXUS FOIAXpress stored XSS via annual report templateopexustech · foiaxpress · CWE-79 | Medium4.8 | — | 0.2% | Oct 7, 2025 |
19Monitor | CVE-2025-61997No exploit | OPEXUS FOIAXpress stored XSS via banner imageopexustech · foiaxpress · CWE-79 | Medium4.8 | — | 0.2% | Oct 7, 2025 |
19Monitor | CVE-2025-61999No exploit | OPEXUS FOIAXpress stored XSS via logo imageopexustech · foiaxpress · CWE-79 | Medium4.8 | — | 0.2% | Oct 7, 2025 |
19Monitor | CVE-2026-22233No exploit | OPEXUS eCASE Audit Project Cost stored XSSopexustech · ecase audit · CWE-79 | Medium4.8 | — | 0.2% | Jan 8, 2026 |
19Monitor | CVE-2026-22232No exploit | OPEXUS eCASE Audit Project Setup stored XSSopexustech · ecase audit · CWE-79 | Medium4.8 | — | 0.2% | Jan 8, 2026 |
19Monitor | CVE-2026-22231No exploit | OPEXUS eCASE Audit Document Check Out stored XSSopexustech · ecase audit · CWE-79 | Medium4.8 | — | 0.2% | Jan 8, 2026 |
- CVE-2025-5846237Monitor
OPEXUS FOIAXpress PAL SQL injection
CriticalCVSS 9.3No exploitEPSS 1%opexustech · foiaxpress public access linkSep 9, 2025
- CVE-2026-2223437Monitor
OPEXUS eCasePortal unauthenticated IDOR
CriticalCVSS 9.3No exploitEPSS 0%opexustech · ecase portalJan 8, 2026
- CVE-2024-5355336Monitor
An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.
CriticalCVSS 9.1No exploitEPSS 1%opexustech · foiaxpress public access linkJan 16, 2025
- CVE-2026-3286536Monitor
OPEXUS eComplaint and eCase insecure password reset
CriticalCVSS 9.2No exploitEPSS 1%opexustech · ecase ecomplaintMar 19, 2026
- CVE-2025-6258635Monitor
OPEXUS FOIAXpress unauthenticated administrator password reset
HighCVSS 8.9No exploitEPSS 1%opexustech · foiaxpressOct 16, 2025
- CVE-2026-2223534Monitor
OPEXUS eComplaint IDOR
HighCVSS 8.7No exploitEPSS 0%opexustech · ecase ecomplaintJan 8, 2026
- CVE-2026-2223028Monitor
OPEXUS eCASE Audit incorrect access control
HighCVSS 7.2No exploitEPSS 0%opexustech · ecase auditJan 8, 2026
- CVE-2025-5483327Monitor
OPEXUS FOIAXpress Public Access Link (PAL) account-lockout and CAPTCHA protection bypass
MediumCVSS 6.9No exploitEPSS 1%opexustech · foiaxpress public access linkJul 31, 2025
- CVE-2025-5483427Monitor
OPEXUS FOIAXpress Public Access Link (PAL) unauthenticated username enumeration
MediumCVSS 6.9No exploitEPSS 0%opexustech · foiaxpress public access linkJul 31, 2025
- CVE-2026-3286721Monitor
OPEXUS eComplaint unauthenticated file upload
MediumCVSS 5.3No exploitEPSS 0%opexustech · ecase ecomplaintMar 19, 2026
- CVE-2025-5483221Monitor
OPEXUS FOIAXpress Public Access Link (PAL) state and territory list unauthorized modification
MediumCVSS 5.3No exploitEPSS 0%opexustech · foiaxpress public access linkJul 31, 2025
- CVE-2026-3286920Monitor
OPEXUS eComplaint and eCASE XSS via Name of Organization field
MediumCVSS 5.1No exploitEPSS 0%opexustech · ecase ecomplaintMar 19, 2026
- CVE-2026-3286620Monitor
OPEXUS eComplaint and eCase stored XSS via profile first and last name
MediumCVSS 5.1No exploitEPSS 0%opexustech · ecase ecomplaintMar 19, 2026
- CVE-2026-3286820Monitor
OPEXUS eComplaint and eCASE XSS via my information
MediumCVSS 5.1No exploitEPSS 0%opexustech · ecase ecomplaintMar 19, 2026
- CVE-2025-6199819Monitor
OPEXUS FOIAXpress stored XSS via Hyperlink Manager
MediumCVSS 4.8No exploitEPSS 0%opexustech · foiaxpressOct 7, 2025
- CVE-2025-6199619Monitor
OPEXUS FOIAXpress stored XSS via annual report template
MediumCVSS 4.8No exploitEPSS 0%opexustech · foiaxpressOct 7, 2025
- CVE-2025-6199719Monitor
OPEXUS FOIAXpress stored XSS via banner image
MediumCVSS 4.8No exploitEPSS 0%opexustech · foiaxpressOct 7, 2025
- CVE-2025-6199919Monitor
OPEXUS FOIAXpress stored XSS via logo image
MediumCVSS 4.8No exploitEPSS 0%opexustech · foiaxpressOct 7, 2025
- CVE-2026-2223319Monitor
OPEXUS eCASE Audit Project Cost stored XSS
MediumCVSS 4.8No exploitEPSS 0%opexustech · ecase auditJan 8, 2026
- CVE-2026-2223219Monitor
OPEXUS eCASE Audit Project Setup stored XSS
MediumCVSS 4.8No exploitEPSS 0%opexustech · ecase auditJan 8, 2026
- CVE-2026-2223119Monitor
OPEXUS eCASE Audit Document Check Out stored XSS
MediumCVSS 4.8No exploitEPSS 0%opexustech · ecase auditJan 8, 2026