8.5
CVE-2019-25310 - ActiveFax Server 6.92 Build 0316 - 'ActiveFaxServiceNT' Unquoted Service Path
ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated adβ¦
8.5
CVE-2019-25309 - Zilab Remote Console Server 3.2.9 - 'Zilab Remote Console Server' Unquoted Service Path
Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will β¦
8.5
CVE-2019-25308 - Mikogo 5.2.2.150317 - 'Mikogo-Service' Unquoted Service Path
Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific path locations.
8.5
CVE-2019-25307 - WorkgroupMail 7.5.1 - 'WorkgroupMail' Unquoted Service Path
WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges durβ¦
8.5
CVE-2019-25306 - BlackMoon FTP Server 3.1.2.1731 - 'BMFTP-RELEASE' Unquoted Serive Path
BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would execute with LocalSystβ¦
5.1
CVE-2018-25157 - Phraseanet 4.0.3 Stored XSS via Document Upload
Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through crafted file names during document uploads. Attackers can upload files with embedded SVG scripts that execute in the browser, potentially stealing cookies or redβ¦
8.6
CVE-2026-2344 - Stored XSS on Plunet BusinessManager
A vulnerability in Plunet Plunet BusinessManager allows unauthorized actions being performed on behalf of privileged users.This issue affects Plunet BusinessManager: 10.15.1
3.6
CVE-2026-2345 - Insufficient Origin Validation in Proctorio Chrome Extension postMessage Handlers
Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based solely onβ¦
7
CVE-2025-61969 -
Incorrect permission assignment in AMD Β΅Prof may allow a local user-privileged attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
7.3
CVE-2025-52541 -
A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.