Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Contact the vendor for the update
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 15 Jan 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gss
Gss vitalsesp |
|
| CPEs | cpe:2.3:a:gss:vitalsesp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gss
Gss vitalsesp |
Tue, 09 Dec 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Galaxy Software Services Corporation
Galaxy Software Services Corporation vitals Esp |
|
| Vendors & Products |
Galaxy Software Services Corporation
Galaxy Software Services Corporation vitals Esp |
Mon, 08 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Dec 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Title | Galaxy Software Services|Vitals ESP - SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-12-08T14:46:02.412Z
Reserved: 2025-12-08T07:12:21.785Z
Link: CVE-2025-14254
Updated: 2025-12-08T14:45:57.186Z
Status : Analyzed
Published: 2025-12-08T08:15:52.260
Modified: 2026-01-15T01:42:14.107
Link: CVE-2025-14254
No data.
OpenCVE Enrichment
Updated: 2025-12-09T10:26:43Z