Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.3
CVE-2024-40408
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerab…
Thinfinity Workspace
7.0.2.113+
CRITICAL 9.8
CVE-2024-40404
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connec…
Thinfinity Workspace
7.0.2.113+
HIGH 8.1
CVE-2024-40405
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafte…
Thinfinity Workspace
7.0.3.109+
HIGH 7.5
CVE-2024-40407
A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unsp…
Thinfinity Workspace
7.0.2.113+
HIGH 8.8
CVE-2022-25227
Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can tr…
Thinfinity Vnc
No fix yet
HIGH 7.5
CVE-2021-46354EPSS 13%
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "A…
Thinfinity Virtualui
No fix yet
MEDIUM 5.3
CVE-2021-44554
Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By access…
Thinfinity Virtualui
3.0+
CRITICAL 9.8
CVE-2021-45092EPSS 40%
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.
Thinfinity Virtualui
3.0+
MEDIUM 5.3
CVE-2021-44848EPSS 23%
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the u…
Thinfinity Virtualui
3.0+
MEDIUM 6.5
CVE-2019-16384
Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web director…
Thinfinity Virtualui
after 2.5.17.2
MEDIUM 6.1
CVE-2019-16385
Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an exa…
Thinfinity Virtualui
after 2.5.17.2
HIGH 7.5
CVE-2015-1429
Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit allows remote attackers to downl…
Thinfinity Remote Desktop Workstation
Mitigation only