Latest CVE Feed
-
8.8
HIGHCVE-2024-42585
A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more
Affected Products : warehouse_inventory_system- Published: Aug. 20, 2024
- Modified: May. 01, 2025
-
8.0
HIGHCVE-2024-42578
A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more
- Published: Aug. 20, 2024
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2024-42576
A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more
Affected Products : warehouse_inventory_system- Published: Aug. 20, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2025-28145
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.... Read more
- Published: Apr. 15, 2025
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2025-28143
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.... Read more
- Published: Apr. 15, 2025
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2025-28142
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.... Read more
- Published: Apr. 15, 2025
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-52884
An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.... Read more
Affected Products : mediant_session_border_controller- Published: Feb. 07, 2025
- Modified: May. 01, 2025
-
5.3
MEDIUMCVE-2024-0855
The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.... Read more
Affected Products : spiffy_calendar- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-52883
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.... Read more
Affected Products : one_voice_operations_center- Published: Feb. 07, 2025
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2024-52882
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.... Read more
Affected Products : one_voice_operations_center- Published: Feb. 07, 2025
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-52881
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.... Read more
Affected Products : one_voice_operations_center- Published: Feb. 07, 2025
- Modified: May. 01, 2025
-
4.8
MEDIUMCVE-2024-40410
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
7.3
HIGHCVE-2024-40408
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-40407
A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
8.1
HIGHCVE-2024-40405
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-40404
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.... Read more
Affected Products : thinfinity_workspace- Published: Nov. 13, 2024
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2024-1106
The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : shariff_wrapper- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
5.3
MEDIUMCVE-2022-45195
SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the... Read more
- EPSS Score: %0.14
- Published: Nov. 12, 2022
- Modified: May. 01, 2025
-
4.7
MEDIUMCVE-2022-45194
CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.... Read more
Affected Products : cbrn-analysis- EPSS Score: %0.09
- Published: Nov. 12, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-45182
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.... Read more
Affected Products : pi-star_digital_voice_dashboard- EPSS Score: %0.44
- Published: Nov. 11, 2022
- Modified: May. 01, 2025