Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gss

First CVE: Jul 21, 2023Active for: 3 yearsTotal CVEs: 9

Gss develops a focused portfolio of enterprise social platforms and analytics products, including VitalsESP, IOTA C.AI, and Vitals Enterprise Social Platform, serving specialized business and data integration use cases. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across input-handling and authentication boundaries through weakness classes such as SQL injection, absolute path traversal, code injection, improper cryptographic signature verification, and incorrect authorization. Defenders tracking this vendor should prioritize patching of its platforms, particularly where they expose integration or administrative interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gss over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 21, 2023
3 years ago
Most Recent CVE
Mar 24, 2026
123 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-4639HIGH
Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform certain administrative functions, t
Mar 24, 20268.830NONO
CVE-2026-4640HIGH
Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to execute certain functions to obtain sensit
Mar 24, 20267.526NONO
CVE-2023-37291CRITICAL
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vul
Jul 21, 20239.826NONO
CVE-2023-41357HIGH
Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated rem
Nov 3, 20238.824NONO
CVE-2025-14255MEDIUM
Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database conten
Dec 8, 20256.522NONO
CVE-2025-14254MEDIUM
Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database conten
Dec 8, 20256.522NONO
CVE-2024-52959HIGH
A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authentic
Nov 27, 20247.220NONO
CVE-2024-52958HIGH
A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated user
Nov 27, 20247.220NONO
CVE-2025-14253MEDIUM
Vitals ESP developed by Galaxy Software Services has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbit
Dec 8, 20254.919NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
56%
11%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (44.4%)
High3 (33.3%)
None2 (22.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gss.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gss — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gss's Products

View all 1 CNAs →

Top CWEs