Uffizio develops a GPS tracking product that exhibits application-layer web-security vulnerabilities, with observed weakness classes centered on input handling and request validation including cross-site scripting, cross-site request forgery, and open redirect flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uffizio over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32929HIGH All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user. | Apr 22, 2022 | 8.8 | 27 | NO | NO |
CVE-2020-17485CRITICAL A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions. The web server can be compromised by uploading and executing a web/reverse shell. An attacker cou | Dec 16, 2023 | 9.8 | 24 | NO | NO |
CVE-2021-32927MEDIUM An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS Tracker. | Apr 22, 2022 | 6.1 | 22 | NO | NO |
CVE-2020-17483HIGH An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information disclosure of all the connected devices. By visiting the vu | Dec 16, 2023 | 7.5 | 20 | NO | NO |
CVE-2020-17484MEDIUM An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrar | Dec 16, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uffizio.
Media articles that mention a CVE ID that affects a product developed by Uffizio — matched by CVE ID, not by vendor name.