Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-32869 OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field when filling out case informat… Ecase Ecomplaint 10.2.0.0+ Fix from $1,6002026-03-19 CRITICAL 9.8 CVE-2026-32865 OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'F… Ecase Ecomplaint 10.1.0.0+ Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-32867 OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files vi… Ecase Ecomplaint 10.1.0.0+ Fix from $2,3002026-03-19 MEDIUM 5.4 CVE-2026-32866 OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a user profile. An authenticated … Ecase Ecomplaint 10.2.0.0+ Fix from $1,6002026-03-19 MEDIUM 5.4 CVE-2026-32868 OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the 'My Information' screen. An a… Ecase Ecomplaint 10.2.0.0+ Fix from $1,6002026-03-19 CRITICAL 9.8 CVE-2026-22234 OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predict… Ecase Portal 9.0.45.0+ Fix from $2,3002026-01-08 HIGH 7.5 CVE-2026-22235 OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'ch… Ecase Ecomplaint 9.0.45.0+ Fix from $1,9502026-01-08 MEDIUM 5.4 CVE-2026-22232 OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project Setup functionality. The Jav… Ecase Audit 11.14.2.0+ Fix from $1,6002026-01-08 MEDIUM 5.4 CVE-2026-22233 OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field. The JavaScript is executed … Ecase Audit 11.14.2.0+ Fix from $1,6002026-01-08 HIGH 7.6 CVE-2026-22230 OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have … Ecase Audit 11.14.1.0+ Fix from $1,9502026-01-08 MEDIUM 5.4 CVE-2026-22231 OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment within the Document Check Out functionality. The JavaScript is ex… Ecase Audit 11.14.1.0+ Fix from $1,6002026-01-08 CRITICAL 9.8 CVE-2025-62586 OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0. Foiaxpress 11.13.2.0+ Fix from $2,3002025-10-16 CRITICAL 9.8 CVE-2025-58462 OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attack… Foiaxpress Public Access Link 11.13.1.0+ Fix from $2,3002025-09-09 HIGH 7.5 CVE-2025-54833 OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote… Foiaxpress Public Access Link 11.12.3.0+ Fix from $1,9502025-07-31 MEDIUM 5.3 CVE-2025-54834 OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint t… Foiaxpress Public Access Link 11.12.3.0+ Fix from $1,6002025-07-31 CRITICAL 9.1 CVE-2024-53553 An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests. Foiaxpress Public Access Link No fix yet Fix from $2,3002025-01-16