Vadesecure's vulnerability profile centers on its secure gateway product, a focused email and web security appliance deployed across enterprise messaging infrastructure. The observed weakness class reflects application-layer input handling, with cross-site scripting concerns recurring in the product's web interface components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vadesecure over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29714MEDIUM Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via the username, password, and language cookies parameter. | Jun 9, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-29713MEDIUM Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the GET request after the /css/ director | Jun 9, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-29712MEDIUM Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the X-Rewrite-URL parameter. | Jun 9, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vadesecure.
Media articles that mention a CVE ID that affects a product developed by Vadesecure — matched by CVE ID, not by vendor name.