Latest CVE Feed
-
3.8
LOWCVE-2023-42238
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_eps.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42237
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42236
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /common/ajaxfunction.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42235
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2023-42234
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.... Read more
Affected Products : helpdeskadvanced- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2023-42233
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.... Read more
Affected Products : helpdeskadvanced- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2023-42232
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.... Read more
Affected Products : helpdeskadvanced- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2023-42231
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending a request to the "WSCView/Delete" function.... Read more
Affected Products : helpdeskadvanced- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2023-42230
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.... Read more
Affected Products : helpdeskadvanced- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2023-42229
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the WSConnector service.... Read more
Affected Products : helpdeskadvanced- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2023-42228
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList/SaveAclRules" administrative function.... Read more
Affected Products : helpdeskadvanced- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2023-42227
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function.... Read more
Affected Products : helpdeskadvanced- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2023-42226
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function.... Read more
Affected Products : helpdeskadvanced- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2023-42225
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.... Read more
Affected Products : helpdeskadvanced- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
6.4
MEDIUMCVE-2025-22619
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `editar_permissoes.php` endpoint of the WeGIA application. This vulnerabili... Read more
Affected Products : wegia- Published: Jan. 13, 2025
- Modified: Feb. 13, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-22618
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_cargo.php` endpoint of the WeGIA application. This vulnerability al... Read more
Affected Products : wegia- Published: Jan. 13, 2025
- Modified: Feb. 13, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-22617
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `editar_socio.php` endpoint of the WeGIA application. This vulnerability al... Read more
Affected Products : wegia- Published: Jan. 13, 2025
- Modified: Feb. 13, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-22616
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `dependente_parentesco_adicionar.php` endpoint of the WeGIA application. This ... Read more
Affected Products : wegia- Published: Jan. 13, 2025
- Modified: Feb. 13, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-22615
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `Cadastro_Atendido.php` endpoint of the WeGIA application. This vulnerabili... Read more
Affected Products : wegia- Published: Jan. 13, 2025
- Modified: Feb. 13, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-22614
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `dependente_editarInfoPessoal.php` endpoint of the WeGIA application. This vul... Read more
Affected Products : wegia- Published: Jan. 13, 2025
- Modified: Feb. 13, 2025