Visualware develops a narrowly scoped network diagnostics and connectivity monitoring platform centered on its MyConnection Server product, which holds prominence in specialized IT operations environments despite a modest vulnerability volume. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and the exposure recurs through web application and access-control weakness classes including cross-site scripting, path traversal, insecure direct object references, XML external entity injection, and improper authorization that reflect both the server's web-facing diagnostic interface and its privileged role in network access. Defenders should treat this vendor's advisories as high-priority for deployed instances given the criticality bias in its disclosures; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Visualware over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27198CRITICAL An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a m | Feb 26, 2021 | 9.8 | 38 | NO | NO |
CVE-2021-27509HIGH In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access code. | Feb 19, 2021 | 7.5 | 23 | NO | NO |
CVE-2023-42034HIGH Visualware MyConnection Server doRTAAccessCTConfig Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on | May 3, 2024 | 8.8 | 22 | NO | NO |
CVE-2023-42032HIGH Visualware MyConnection Server doRTAAccessUPass Exposed Dangerous Method Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive info | May 3, 2024 | 7.5 | 20 | NO | NO |
CVE-2023-42035MEDIUM Visualware MyConnection Server doIForward XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive info | May 3, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-42033HIGH Visualware MyConnection Server doPostUploadfiles Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af | May 3, 2024 | 7.2 | 19 | NO | NO |
CVE-2014-5113MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in test.php in Visualware MyConnection Server 9.7i allow remote attackers to inject arbitrary web script or HTML via the (1) tes | Jul 28, 2014 | 4.3 | 17 | NO | NO |
CVE-2015-2043MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Visualware MyConnection Server 8.2b allow remote attackers to inject arbitrary web script or HTML via the (1) bt, (2) variabl | Feb 25, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Visualware.
Media articles that mention a CVE ID that affects a product developed by Visualware — matched by CVE ID, not by vendor name.