Gruparge's vulnerability profile centers on its SmartPower web and power-management product line, a modestly represented but strategically positioned set of tools in industrial control and facility management environments. The vendor's disclosures skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around common web-application weaknesses including cross-site scripting, SQL injection, improper input validation, and server-side request forgery that reflect the internet-facing nature and data-handling demands of management interfaces. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gruparge over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4557CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection.
Th | Feb 12, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-45088CRITICAL Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File Inclusion.
This issue affects Smartpower Web: before 23.01.01 | Feb 12, 2023 | 9.8 | 28 | NO | NO |
CVE-2022-45090HIGH Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection.
This issue affects Smartpower Web: before 23.01.01. | Feb 12, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-45089HIGH Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection.
This issue affects Smartpower Web: before 23.01.01. | Feb 12, 2023 | 8.8 | 26 | NO | NO |
CVE-2022-45087MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripti | Feb 12, 2023 | 6.1 | 21 | NO | NO |
CVE-2022-45085MEDIUM Server-Side Request Forgery (SSRF) vulnerability in Group Arge Energy and Control Systems Smartpower Web allows : Server Side Request Forgery.
This issue affects Smartpower Web: b | Feb 12, 2023 | 6.5 | 21 | NO | NO |
CVE-2022-45091MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripti | Feb 12, 2023 | 5.4 | 19 | NO | NO |
CVE-2022-45086MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripti | Feb 12, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gruparge.
Media articles that mention a CVE ID that affects a product developed by Gruparge — matched by CVE ID, not by vendor name.