Web Audimex maintains a focused product line centered on its Audimex and AudimexEE applications, which appear to serve a specialized role in web auditing and compliance workflows. The vulnerability profile for this vendor is narrow in scope with a durable signal concentrated around these applications, and live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Web Audimex over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36361CRITICAL Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter. | Sep 5, 2023 | 9.8 | 28 | NO | NO |
CVE-2020-28115HIGH SQL Injection vulnerability in "Documents component" found in AudimexEE version 14.1.0 allows an attacker to execute arbitrary SQL commands via the object_path parameter. | Nov 5, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-28047MEDIUM AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration parameter "unique_error_numbers" is not set, remote attacke | Nov 5, 2020 | 5.4 | 19 | NO | NO |
CVE-2023-46396MEDIUM Audimex 15.0.0 is vulnerable to Cross Site Scripting (XSS) in /audimex/cgi-bin/wal.fcgi via company parameter search filters. | Oct 25, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-39558MEDIUM AudimexEE v15.0 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the Show Kai Data component. | Aug 29, 2023 | 6.1 | 18 | NO | NO |
CVE-2024-30889MEDIUM Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execute arbitrary code via the service, method, widget_type, requ | Jun 4, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-39559MEDIUM AudimexEE 15.0 was discovered to contain a full path disclosure vulnerability. | Aug 29, 2023 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Web Audimex.
Media articles that mention a CVE ID that affects a product developed by Web Audimex — matched by CVE ID, not by vendor name.