Vice develops library and catalog management software, notably WebOPAC and related products, with vulnerabilities that skew strongly toward critical-severity outcomes. The exposure reflects common input-handling and file-management risks in web-facing applications, including cross-site scripting, SQL injection, and unrestricted file uploads. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vice over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11020CRITICAL Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database conten | Nov 11, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-11018CRITICAL Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrar | Nov 11, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-11016CRITICAL Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database conten | Nov 11, 2024 | 9.8 | 29 | NO | NO |
CVE-2021-42839HIGH Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script | Nov 15, 2021 | 8.8 | 27 | NO | NO |
CVE-2024-11017HIGH Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to | Nov 11, 2024 | 8.8 | 26 | NO | NO |
CVE-2021-42838MEDIUM Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thus unauthenticated attackers can inject JavaScript syntax rem | Nov 15, 2021 | 6.1 | 21 | NO | NO |
CVE-2024-11021MEDIUM Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When user | Nov 11, 2024 | 5.4 | 19 | NO | NO |
CVE-2004-0453HIGH Format string vulnerability in the monitor "memory dump" command in VICE 1.6 to 1.14 allows local users to cause a denial of service (emulator crash) and possibly execute arbitrary | Aug 6, 2004 | 7.2 | 18 | NO | NO |
CVE-2024-11019MEDIUM Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browse | Nov 11, 2024 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vice.
Media articles that mention a CVE ID that affects a product developed by Vice — matched by CVE ID, not by vendor name.