Oceanicsoft develops ValeApp, a web application whose vulnerability footprint reflects recurring issues in data protection and input handling, including cleartext storage of sensitive information and credentials, XSS, SQL injection, and log-file information leakage. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oceanicsoft over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8643CRITICAL Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking.
This issue affects ValeApp: before v2.0.0. | Sep 27, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-8607CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software ValeApp allows SQL Injection.
This issue affects ValeApp: be | Sep 27, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-8644HIGH Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking).
This is | Sep 27, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-8609HIGH Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Information.
This issue affects ValeApp: before v2.0.0. | Sep 27, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-8608MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Oceanic Software ValeApp allows Stored XSS.
This issue affects ValeApp | Sep 27, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oceanicsoft.
Media articles that mention a CVE ID that affects a product developed by Oceanicsoft — matched by CVE ID, not by vendor name.