Bilanc is a focused provider of financial and business management software where the observed vulnerability signal centers on the core product's handling of credentials and sensitive data transmission. The recurring weakness classes—hard-coded credentials, cleartext transmission of sensitive information, and SQL injection—reflect common application-layer input validation and secrets-management shortcomings. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bilanc over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8995CRITICAL Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to different servers that allow remote attackers to gain access to th | Dec 21, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-11720CRITICAL An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation, it sets up administrative access by default with the accoun | Dec 23, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-11717CRITICAL An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities. | Dec 21, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-11719HIGH An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encryption with a weak and guessable static encryption key. | Dec 23, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-11718HIGH An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP. | Dec 23, 2020 | 7.4 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bilanc.
Media articles that mention a CVE ID that affects a product developed by Bilanc — matched by CVE ID, not by vendor name.