Asseco operates in the enterprise software space with a narrow vulnerability footprint concentrated around its DVS Avilys product, a specialized system likely serving financial or administrative infrastructure. The observed weakness classes center on information-exposure issues: improper access controls allowing external parties to reach sensitive files and directories, and inadvertent logging of sensitive data, reflecting challenges in controlling data visibility across system components. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asseco over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27192HIGH The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administ | Mar 23, 2022 | 7.5 | 25 | NO | NO |
CVE-2025-66955MEDIUM Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in th | Mar 12, 2026 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asseco.
Media articles that mention a CVE ID that affects a product developed by Asseco — matched by CVE ID, not by vendor name.