Gov encompasses a small set of government and administrative software products, including case-management and tax-filing systems such as CCD Data Store API and Imposto de Renda da Pessoa Física, where the observed vulnerability signal centers on input-handling weaknesses including SQL injection and improper neutralization of special elements. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gov over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15569CRITICAL HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java. | Aug 26, 2019 | 9.8 | 28 | NO | NO |
CVE-2020-12717MEDIUM The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement | May 14, 2020 | 6.5 | 18 | NO | NO |
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature. | Jun 12, 2021 | 3.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gov.
Media articles that mention a CVE ID that affects a product developed by Gov — matched by CVE ID, not by vendor name.