Gotac's vulnerability footprint centers on specialized law-enforcement database systems such as its Police Statistics Database, a niche but security-sensitive product category. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through structural weaknesses in access control and file handling—absolute and relative path traversal, missing authentication for critical functions, and unrestricted file uploads—that reflect the administrative and data-ingestion demands of institutional database platforms. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gotac over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1021CRITICAL Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload and execute web shell backdoors, | Jan 16, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-1019CRITICAL Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database cont | Jan 16, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-1018HIGH Police Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing Unauthenticated remote attacker to exploit Absolute Path Traversal to downlo | Jan 16, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-1023HIGH Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly exploit a specific functionality to | Jan 16, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-1020MEDIUM Police Statistics Database System developed by Gotac has a Absolute Path Traversal vulnerability, allowing unauthenticated remote attackers to enumerate the system file directory. | Jan 16, 2026 | 5.3 | 23 | NO | NO |
CVE-2026-1022HIGH Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arb | Jan 16, 2026 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gotac.
Media articles that mention a CVE ID that affects a product developed by Gotac — matched by CVE ID, not by vendor name.