Uni Yaz produces a narrow set of water-management and utility-infrastructure software products, including FlexCity and FlexWater Corporate Water Management, which serve specialized operational and administrative roles. The vendor's observed vulnerability surface has been modest in scope with no clear recurring weakness classes established. Current vulnerability counts, exploitation activity, and severity breakdowns are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uni Yaz over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1618HIGH Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows Privilege Escalation.
This issue affects FlexCity/Kiosk: fr | Feb 13, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-14349HIGH Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Accessing Functionality Not Prope | Feb 13, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-1619HIGH Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers.
This issue affects FlexCity/Ki | Feb 13, 2026 | 8.3 | 27 | NO | NO |
CVE-2024-0857CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc. FlexWater Corporate Water Management allows SQL Inject | Jul 18, 2024 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uni Yaz.
Media articles that mention a CVE ID that affects a product developed by Uni Yaz — matched by CVE ID, not by vendor name.