Digitro's vulnerability profile centers on NGC Explorer, a web-based application where the durable signal reflects client-side security implementation and session-management weaknesses, including client-side enforcement of server-side controls, sensitive-information exposure, insufficient session expiration, and missing password field masking. These recurring patterns suggest architectural reliance on client-side validation and inadequate server-side enforcement of security boundaries; treat this as a compact vendor profile rather than a broad trend line. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digitro over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-4528CRITICAL A weakness has been identified in Dígitro NGC Explorer up to 3.44.15/3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack | May 11, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-4526MEDIUM A vulnerability was identified in Dígitro NGC Explorer up to 3.44.15/3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation lea | May 11, 2025 | 5.5 | 17 | NO | NO |
CVE-2025-4527MEDIUM A security flaw has been discovered in Dígitro NGC Explorer up to 3.44.15/3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Perfo | May 11, 2025 | 5.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digitro.
Media articles that mention a CVE ID that affects a product developed by Digitro — matched by CVE ID, not by vendor name.