Omnis is a low-volume application development platform centered on its Studio product, with a narrow but persistent vulnerability footprint reflecting the platform's role in enterprise application construction. The observed weakness classes cluster around default permissions and configuration, typical of platform-layer software where deployment guidance and access-control defaults carry weight for downstream applications. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Omnis over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0449HIGH Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields. | May 1, 2000 | 10.0 | 35 | NO | YES |
CVE-2023-38334MEDIUM Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, vie | Jul 20, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-38335MEDIUM Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, | Jul 20, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Omnis.
Media articles that mention a CVE ID that affects a product developed by Omnis — matched by CVE ID, not by vendor name.