Latest CVE Feed
-
7.5
HIGHCVE-2024-52883
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.... Read more
Affected Products : one_voice_operations_center- Published: Feb. 07, 2025
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2024-52882
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.... Read more
Affected Products : one_voice_operations_center- Published: Feb. 07, 2025
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-52881
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.... Read more
Affected Products : one_voice_operations_center- Published: Feb. 07, 2025
- Modified: May. 01, 2025
-
4.8
MEDIUMCVE-2024-40410
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
7.3
HIGHCVE-2024-40408
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-40407
A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
8.1
HIGHCVE-2024-40405
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-40404
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2024-1106
The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : shariff_wrapper- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
5.3
MEDIUMCVE-2022-45195
SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the... Read more
- EPSS Score: %0.14
- Published: Nov. 12, 2022
- Modified: May. 01, 2025
-
4.7
MEDIUMCVE-2022-45194
CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.... Read more
Affected Products : cbrn-analysis- EPSS Score: %0.09
- Published: Nov. 12, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-45182
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.... Read more
Affected Products : pi-star_digital_voice_dashboard- EPSS Score: %0.44
- Published: Nov. 11, 2022
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2022-45130
Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so t... Read more
Affected Products : obsidian- EPSS Score: %0.39
- Published: Nov. 10, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-45129
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2... Read more
Affected Products : payara- EPSS Score: %1.57
- Published: Nov. 10, 2022
- Modified: May. 01, 2025
-
9.1
CRITICALCVE-2022-44727
The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).... Read more
Affected Products : eu_cookie_law_gdpr- EPSS Score: %0.29
- Published: Nov. 10, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-44561
The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction.... Read more
- EPSS Score: %0.07
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
5.3
MEDIUMCVE-2022-44560
The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified.... Read more
- EPSS Score: %0.07
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-44559
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.... Read more
- EPSS Score: %0.28
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-44558
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.... Read more
- EPSS Score: %0.28
- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2022-44557
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.... Read more
- EPSS Score: %0.09
- Published: Nov. 09, 2022
- Modified: May. 01, 2025