Agilepoint develops a workflow and business-process management platform centered on its NX product, which has surfaced vulnerabilities rooted in input handling and file-upload controls such as path traversal, SQL injection, and unrestricted file uploads. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Agilepoint over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24507CRITICAL
AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request.
| May 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-31178CRITICAL AgilePoint NX v8.0 SU2.2 & SU2.3 – Arbitrary File Delete Vulnerability allows arbitrary file deletion, by an unspecified request.
| May 8, 2023 | 9.1 | 27 | NO | NO |
CVE-2022-30619HIGH Editable SQL Queries behind Base64 encoding sending from the Client-Side to The Server-Side for a particular API used in legacy Work Center module. He attack is available for any a | Jul 6, 2022 | 8.8 | 27 | NO | NO |
CVE-2023-31179HIGH AgilePoint NX v8.0 SU2.2 & SU2.3 - Path traversal - Vulnerability allows path traversal and downloading files from the server, by an unspecified request.
| May 8, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Agilepoint.
Media articles that mention a CVE ID that affects a product developed by Agilepoint — matched by CVE ID, not by vendor name.