Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thinfinity Workspace HIGH 7.3
CVE-2024-40408

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerab…

Fix: 7.0.2.113+
Fix from $1,950 2024-11-13
Thinfinity Workspace CRITICAL 9.8
CVE-2024-40404

Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connec…

Fix: 7.0.2.113+
Fix from $2,300 2024-11-13
Thinfinity Workspace HIGH 8.1
CVE-2024-40405

Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafte…

Fix: 7.0.3.109+
Fix from $1,950 2024-11-13
Thinfinity Workspace HIGH 7.5
CVE-2024-40407

A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unsp…

Fix: 7.0.2.113+
Fix from $1,950 2024-11-13
Thinfinity Vnc HIGH 8.8
CVE-2022-25227

Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can tr…

No fix yet
Fix from $1,950 2022-05-20
Thinfinity Virtualui HIGH 7.5
CVE-2021-46354EPSS 13%

Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "A…

No fix yet
Fix from $1,950 2022-02-09
Thinfinity Virtualui MEDIUM 5.3
CVE-2021-44554

Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By access…

Fix: 3.0+
Fix from $1,600 2021-12-20
Thinfinity Virtualui CRITICAL 9.8
CVE-2021-45092EPSS 40%

Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.

Fix: 3.0+
Fix from $2,300 2021-12-16
Thinfinity Virtualui MEDIUM 5.3
CVE-2021-44848EPSS 23%

In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the u…

Fix: 3.0+
Fix from $1,600 2021-12-13
Thinfinity Virtualui MEDIUM 6.5
CVE-2019-16384

Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web director…

Fix: after 2.5.17.2
Fix from $1,600 2020-06-04
Thinfinity Virtualui MEDIUM 6.1
CVE-2019-16385

Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an exa…

Fix: after 2.5.17.2
Fix from $1,600 2020-06-04
Thinfinity Remote Desktop Workstation HIGH 7.5
CVE-2015-1429

Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit allows remote attackers to downl…

Mitigation only
Fix from $1,950 2017-10-06