Venki maintains a focused business-process management platform, Supravizio BPM, with a durable vulnerability signal centered on authentication and input-handling weaknesses including brute-force resistance, credential protection, open redirects, and unrestricted file uploads. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Venki over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-46479HIGH Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote code | Jan 13, 2025 | 8.8 | 24 | NO | NO |
CVE-2020-15367CRITICAL Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication atta | Jul 7, 2020 | 9.8 | 24 | NO | NO |
CVE-2024-46480HIGH An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on the underlying host system. | Jan 13, 2025 | 7.2 | 21 | NO | NO |
CVE-2024-46481MEDIUM The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS. | Jan 13, 2025 | 6.1 | 18 | NO | NO |
CVE-2020-15392MEDIUM A user enumeration vulnerability flaw was found in Venki Supravizio BPM 10.1.2. This issue occurs during password recovery, where a difference in error messages could allow an atta | Jul 7, 2020 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Venki.
Media articles that mention a CVE ID that affects a product developed by Venki — matched by CVE ID, not by vendor name.