Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-46481

    The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS.

    Last Modified: Oct 03, 2025
    Published: Jan 13, 2025

    CVE-2024-46479

    Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote code execution.

    Last Modified: Oct 07, 2025
    Published: Jan 13, 2025

    CVE-2024-46480

    An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on the underlying host system.

    Last Modified: Oct 03, 2025
    Published: Jan 13, 2025

    CVE-2020-15367

    Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.

    Last Modified: Nov 21, 2024
    Published: Jul 07, 2020

    CVE-2020-15392

    A user enumeration vulnerability flaw was found in Venki Supravizio BPM 10.1.2. This issue occurs during password recovery, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames.

    Last Modified: Nov 21, 2024
    Published: Jul 07, 2020
    Items Per Page
    Venki Vulnerabilities & Security CVEs | CVE-DB