Secudos develops a focused portfolio of enterprise security and access-management products—including Domos, Qiata, and Qiata FTA—that handle authentication, authorization, and administrative access control. Vulnerabilities affecting these products recur through input-handling and privilege-management weakness classes including cross-site scripting, path traversal, OS command injection, and incorrect permission assignment, reflecting the exposure surface inherent to identity and access-control systems; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Secudos over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18665HIGH The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion. | Nov 2, 2019 | 7.5 | 42 | NO | YES |
CVE-2023-40361HIGH SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMO | Oct 20, 2023 | 7.8 | 22 | NO | NO |
CVE-2020-14293HIGH conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacters in the zone field (obtained from the web interface). | Oct 2, 2020 | 7.5 | 21 | NO | NO |
CVE-2020-14294MEDIUM An issue was discovered in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when reading transfer comments or the global notice board. | Oct 2, 2020 | 6.1 | 20 | NO | NO |
CVE-2019-18664MEDIUM The Log module in SECUDOS DOMOS before 5.6 allows XSS. | Nov 2, 2019 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Secudos.
Media articles that mention a CVE ID that affects a product developed by Secudos — matched by CVE ID, not by vendor name.