Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-61431
A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchet…
Infinity Zmaintenance
after 4.1
MEDIUM 6.1
CVE-2025-52180
Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated attackers to inject arbitrary Jav…
Ad Hoc Infinity
after 4.2
HIGH 7.6
CVE-2024-51321
In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled websi…
Ad Hoc Infinity
No fix yet
HIGH 7.3
CVE-2024-51319
A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Ex…
Ad Hoc Infinity
No fix yet
MEDIUM 5.4
CVE-2024-51320
Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servle…
Ad Hoc Infinity
No fix yet
MEDIUM 5.4
CVE-2024-51322
Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/ho…
Ad Hoc Infinity
No fix yet
HIGH 8.1
CVE-2023-42231
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending …
Helpdeskadvanced
after 11.0.33
HIGH 7.5
CVE-2023-42232
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.
Helpdeskadvanced
after 11.0.33
MEDIUM 6.1
CVE-2023-42230
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.
Helpdeskadvanced
after 11.0.33
MEDIUM 6.1
CVE-2023-42233
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.
Helpdeskadvanced
after 11.0.33
MEDIUM 5.4
CVE-2023-42234
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.
Helpdeskadvanced
after 11.0.33
HIGH 8.8
CVE-2023-42228
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by se…
Helpdeskadvanced
after 11.0.33
HIGH 7.5
CVE-2023-42225
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.
Helpdeskadvanced
after 11.0.33
HIGH 7.5
CVE-2023-42226
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function.
Helpdeskadvanced
after 11.0.33
HIGH 7.5
CVE-2023-42227
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function.
Helpdeskadvanced
after 11.0.33
MEDIUM 6.5
CVE-2023-42229
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticat…
Helpdeskadvanced
after 11.0.33
HIGH 8.8
CVE-2021-42369
Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "…
Imagicle Uc Suite
2021.summer.2+
MEDIUM 5.4
CVE-2019-18207
In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field…
Infobusiness
after 4.4.1
HIGH 8.8
CVE-2019-18204
Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.
Infobusiness
after 4.4.1
HIGH 8.8
CVE-2019-18206
A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.
Infobusiness
after 4.4.1
MEDIUM 6.1
CVE-2019-18205
Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did …
Infobusiness
after 4.4.1
HIGH 7.5
CVE-2019-10257
Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restricted location (dot-dot-slash…
Hr Portal
after 2019-03-15