6.5

CVSS3.1

CVE-2023-42248 -

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php".

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 4:34 p.m.

6.1

CVSS3.1

CVE-2023-42247 -

Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 4:34 p.m.

6.1

CVSS3.1

CVE-2023-42245 -

Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 4:34 p.m.

3.8

CVSS3.1

CVE-2023-42237 -

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 4:35 p.m.

6.5

CVSS3.1

CVE-2023-42229 -

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the WSConnector service.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 5:43 p.m.

6.5

CVSS3.1

CVE-2024-54999 -

MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 7, 2025, 4:49 p.m.

8.4

CVSS3.1

CVE-2024-46480 -

An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privileges on the underlying host system.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 3, 2025, 1:42 p.m.

3.8

CVSS3.1

CVE-2023-42240 -

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /monitor/s_scheduledfile.php.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 4:34 p.m.

8.1

CVSS3.1

CVE-2023-42231 -

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending a request to the "WSCView/Delete" function.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 5:44 p.m.

6.1

CVSS3.1

CVE-2023-42246 -

Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php.

๐Ÿ“… Published: Jan. 13, 2025, midnight ๐Ÿ”„ Last Modified: April 17, 2025, 4:34 p.m.
Total resulsts: 347742
Page 7030 of 34,775
ยซ previous page ยป next page
Filters