Velneo develops a modestly represented line of business applications centered on its VClient product, with a durable signal focused on authentication and certificate-handling weaknesses. The observed vulnerability pattern reflects input-trust and credential-validation challenges typical of client-server application architectures. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Velneo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45036HIGH Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server. | Nov 28, 2022 | 7.4 | 25 | NO | NO |
CVE-2021-45035MEDIUM Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has access to the network to perform a | Sep 23, 2022 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Velneo.
Media articles that mention a CVE ID that affects a product developed by Velneo — matched by CVE ID, not by vendor name.