Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Infinity Zmaintenance MEDIUM 6.1
CVE-2025-61431

A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchet…

Fix: after 4.1
Fix from $1,600 2025-11-04
Ad Hoc Infinity MEDIUM 6.1
CVE-2025-52180

Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated attackers to inject arbitrary Jav…

Fix: after 4.2
Fix from $1,600 2025-10-30
Ad Hoc Infinity HIGH 7.6
CVE-2024-51321

In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled websi…

No fix yet
Fix from $1,950 2025-03-11
Ad Hoc Infinity HIGH 7.3
CVE-2024-51319

A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Ex…

No fix yet
Fix from $1,950 2025-03-11
Ad Hoc Infinity MEDIUM 5.4
CVE-2024-51320

Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servle…

No fix yet
Fix from $1,600 2025-03-11
Ad Hoc Infinity MEDIUM 5.4
CVE-2024-51322

Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/ho…

No fix yet
Fix from $1,600 2025-03-11
Helpdeskadvanced HIGH 8.1
CVE-2023-42231

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending …

Fix: after 11.0.33
Fix from $1,950 2025-01-13
Helpdeskadvanced HIGH 7.5
CVE-2023-42232

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.

Fix: after 11.0.33
Fix from $1,950 2025-01-13
Helpdeskadvanced MEDIUM 6.1
CVE-2023-42230

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.

Fix: after 11.0.33
Fix from $1,600 2025-01-13
Helpdeskadvanced MEDIUM 6.1
CVE-2023-42233

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.

Fix: after 11.0.33
Fix from $1,600 2025-01-13
Helpdeskadvanced MEDIUM 5.4
CVE-2023-42234

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.

Fix: after 11.0.33
Fix from $1,600 2025-01-13
Helpdeskadvanced HIGH 8.8
CVE-2023-42228

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by se…

Fix: after 11.0.33
Fix from $1,950 2025-01-13
Helpdeskadvanced HIGH 7.5
CVE-2023-42225

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.

Fix: after 11.0.33
Fix from $1,950 2025-01-13
Helpdeskadvanced HIGH 7.5
CVE-2023-42226

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function.

Fix: after 11.0.33
Fix from $1,950 2025-01-13
Helpdeskadvanced HIGH 7.5
CVE-2023-42227

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function.

Fix: after 11.0.33
Fix from $1,950 2025-01-13
Helpdeskadvanced MEDIUM 6.5
CVE-2023-42229

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticat…

Fix: after 11.0.33
Fix from $1,600 2025-01-13
Imagicle Uc Suite HIGH 8.8
CVE-2021-42369

Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "…

Fix: 2021.summer.2+
Fix from $1,950 2021-10-14
Infobusiness MEDIUM 5.4
CVE-2019-18207

In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field…

Fix: after 4.4.1
Fix from $1,600 2019-10-30
Infobusiness HIGH 8.8
CVE-2019-18204

Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.

Fix: after 4.4.1
Fix from $1,950 2019-10-30
Infobusiness HIGH 8.8
CVE-2019-18206

A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.

Fix: after 4.4.1
Fix from $1,950 2019-10-30
Infobusiness MEDIUM 6.1
CVE-2019-18205

Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did …

Fix: after 4.4.1
Fix from $1,600 2019-10-30
Hr Portal HIGH 7.5
CVE-2019-10257

Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restricted location (dot-dot-slash…

Fix: after 2019-03-15
Fix from $1,950 2019-06-19