Auvesy develops VersionDog, a version-control and release-management platform widely used in industrial and enterprise environments to track configuration and software changes. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through weakness classes including resource-exhaustion flaws, out-of-bounds writes, authentication bypasses, and path-manipulation issues that reflect the product's role in managing access to sensitive software artifacts and system configurations. Defenders should prioritize patching this vendor's disclosures given the elevation in severity and the access-control functions the product performs; live exploitation status and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Auvesy over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38459CRITICAL The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the | Oct 22, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-38477CRITICAL There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and/or the deletion of files. | Oct 22, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-38457CRITICAL The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication. | Oct 22, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-38481CRITICAL The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of the supplied JOB ID provided to the function. An attacker ma | Oct 22, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-38471CRITICAL There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files. | Oct 22, 2021 | 9.1 | 29 | NO | NO |
CVE-2021-38449CRITICAL Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these parameters, an attacker could rewrite the memory in any location of | Oct 22, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-38475HIGH The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions. | Oct 22, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-38473HIGH The affected product’s code base doesn’t properly control arguments for specific functions, which could lead to a stack overflow. | Oct 22, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-38453CRITICAL Some API functions allow interaction with the registry, which includes reading values as well as data modification. | Oct 22, 2021 | 9.1 | 27 | NO | NO |
CVE-2021-38467HIGH A specific function code receives a raw pointer supplied by the user and deallocates this pointer. The user can then control what memory regions will be freed and cause use-after-f | Oct 22, 2021 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Auvesy.
Media articles that mention a CVE ID that affects a product developed by Auvesy — matched by CVE ID, not by vendor name.