Iagona maintains a focused vulnerability profile centered on ScrutisWeb, a web-based compliance and audit platform, with the durable signal concentrated in application-layer weaknesses including unrestricted file uploads and hard-coded credentials. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iagona over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-35189CRITICAL Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a remote
code execution vulnerability that could allow an unauthenticated user to
upload a malicious payload and exe | Jul 18, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-33871HIGH Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a directory traversal vulnerability that could allow an unauthenticated user to directly access any file outside the w | Jul 18, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-38257HIGH Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to an insecure direct object reference vulnerability that could allow an unauthenticated user to view profile information | Jul 18, 2023 | 7.5 | 19 | NO | NO |
CVE-2023-35763MEDIUM Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a cryptographic vulnerability that could allow an unauthenticated user to decrypt encrypted passwords into plaintext. | Jul 18, 2023 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iagona.
Media articles that mention a CVE ID that affects a product developed by Iagona — matched by CVE ID, not by vendor name.