Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pro Cloud Server HIGH 7.5
CVE-2026-42100

Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an spe…

Fix: after 6.1.167
Fix from $1,950 2026-05-19
Pro Cloud Server HIGH 8.8
CVE-2026-42096

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privi…

Fix: after 6.1.167
Fix from $1,950 2026-05-19
Pro Cloud Server HIGH 8.8
CVE-2026-42097

Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only …

Fix: after 6.1.167
Fix from $1,950 2026-05-19
Pro Cloud Server HIGH 7.5
CVE-2026-42099

Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties…

Fix: after 6.1.167
Fix from $1,950 2026-05-19
Pro Cloud Server CRITICAL 9.8
CVE-2025-15625

Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.

Mitigation only
Fix from $2,300 2026-04-17
Pro Cloud Server HIGH 7.5
CVE-2025-15623

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulne…

Mitigation only
Fix from $1,950 2026-04-17
Pro Cloud Server HIGH 7.5
CVE-2025-15624

Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID is used as the primary metho…

Mitigation only
Fix from $1,950 2026-04-17
Enterprise Architect CRITICAL 9.8
CVE-2022-47072

SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Sel…

No fix yet
Fix from $2,300 2024-01-31