8.6

CVSS4.0

CVE-2025-41077 - Multiple vulnerabilities in Viafirma products

IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password recovery functionality to…

📅 Published: Jan. 12, 2026, 2:54 p.m. 🔄 Last Modified: Jan. 29, 2026, 8:09 p.m.

9.3

CVSS4.0

CVE-2025-41006 - Multiple vulnerabilities in Imaster products Open configuration options

Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.

📅 Published: Jan. 12, 2026, 2:39 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-41005 - Multiple vulnerabilities in Imaster products Open configuration options

Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.php’.

📅 Published: Jan. 12, 2026, 2:35 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-41004 - Multiple vulnerabilities in Imaster products Open configuration options

Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/complaints.php’ through the ‘id’ parameter.

📅 Published: Jan. 12, 2026, 1:55 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-41003 - Multiple vulnerabilities in Imaster products Open configuration options

Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint ‘/projects/hospital/admin/edit_patient.php’. By injecting a malicious script into the ‘firstname’ parameter, the JavaScript code is stored and executed every time a user accesses th…

📅 Published: Jan. 12, 2026, 1:50 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-40978 - Multiple vulnerabilities in WorkDo products

Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request to ‘/ticket/x/conversion’, using the ‘reply_description’ parameter.

📅 Published: Jan. 12, 2026, 11:28 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-40977 - Multiple vulnerabilities in WorkDo products

Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a lack of proper validation of user input by sending a POST request to ‘/store-ticket’, using the ‘subject’ and ‘description’ parameters.

📅 Published: Jan. 12, 2026, 11:28 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-40976 - Multiple vulnerabilities in WorkDo products

Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's TicketGo, consisting of a lack of proper validation of user input by sending a POST request to ‘/ticketgo-saas/home’, using the ‘description’ parameter.

📅 Published: Jan. 12, 2026, 11:27 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-40975 - Multiple vulnerabilities in WorkDo products

Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's HRMGo, consisting of a lack of proper validation of user input by sending a POST request to ‘/hrmgo/ticket/changereply’, using the ‘description’ parameter.

📅 Published: Jan. 12, 2026, 11:26 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2026-22837 -

Not used

📅 Published: Jan. 12, 2026, 8:32 a.m. 🔄 Last Modified: Jan. 13, 2026, 3:55 a.m.
Total resulsts: 349182
Page 2193 of 34,919
« previous page » next page
Filters