GrupargeCVEs & Vulnerabilities

8 CVEs affecting Gruparge products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

smartpower web 7smartpower 1
CVE-2022-4557CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.

12 Feb 2023
9.8
CVSS
CVE-2022-45091MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripting (XSS). This issue affects Smartpower Web: before 23.01.01.

12 Feb 2023
5.4
CVSS
CVE-2022-45090HIGH

Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.

12 Feb 2023
8.8
CVSS
CVE-2022-45089HIGH

Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.

12 Feb 2023
8.8
CVSS
CVE-2022-45088CRITICAL

Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File Inclusion. This issue affects Smartpower Web: before 23.01.01.

12 Feb 2023
9.8
CVSS
CVE-2022-45087MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripting (XSS). This issue affects Smartpower Web: before 23.01.01.

12 Feb 2023
6.1
CVSS
CVE-2022-45086MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripting (XSS). This issue affects Smartpower Web: before 23.01.01.

12 Feb 2023
5.4
CVSS
CVE-2022-45085MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Group Arge Energy and Control Systems Smartpower Web allows : Server Side Request Forgery. This issue affects Smartpower Web: before 23.01.01.

12 Feb 2023
6.5
CVSS
← PrevPage 1 / 1Next →
Gruparge CVEs & Vulnerabilities — 8 Tracked