Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-61431 A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchet… Infinity Zmaintenance after 4.1 Fix from $1,6002025-11-04 MEDIUM 6.1 CVE-2025-52180 Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated attackers to inject arbitrary Jav… Ad Hoc Infinity after 4.2 Fix from $1,6002025-10-30 HIGH 7.6 CVE-2024-51321 In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled websi… Ad Hoc Infinity No fix yet Fix from $1,9502025-03-11 HIGH 7.3 CVE-2024-51319 A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Ex… Ad Hoc Infinity No fix yet Fix from $1,9502025-03-11 MEDIUM 5.4 CVE-2024-51320 Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servle… Ad Hoc Infinity No fix yet Fix from $1,6002025-03-11 MEDIUM 5.4 CVE-2024-51322 Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/ho… Ad Hoc Infinity No fix yet Fix from $1,6002025-03-11 HIGH 8.1 CVE-2023-42231 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending … Helpdeskadvanced after 11.0.33 Fix from $1,9502025-01-13 HIGH 7.5 CVE-2023-42232 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function. Helpdeskadvanced after 11.0.33 Fix from $1,9502025-01-13 MEDIUM 6.1 CVE-2023-42230 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function. Helpdeskadvanced after 11.0.33 Fix from $1,6002025-01-13 MEDIUM 6.1 CVE-2023-42233 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function. Helpdeskadvanced after 11.0.33 Fix from $1,6002025-01-13 MEDIUM 5.4 CVE-2023-42234 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function. Helpdeskadvanced after 11.0.33 Fix from $1,6002025-01-13 HIGH 8.8 CVE-2023-42228 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by se… Helpdeskadvanced after 11.0.33 Fix from $1,9502025-01-13 HIGH 7.5 CVE-2023-42225 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function. Helpdeskadvanced after 11.0.33 Fix from $1,9502025-01-13 HIGH 7.5 CVE-2023-42226 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function. Helpdeskadvanced after 11.0.33 Fix from $1,9502025-01-13 HIGH 7.5 CVE-2023-42227 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function. Helpdeskadvanced after 11.0.33 Fix from $1,9502025-01-13 MEDIUM 6.5 CVE-2023-42229 Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticat… Helpdeskadvanced after 11.0.33 Fix from $1,6002025-01-13 HIGH 8.8 CVE-2021-42369 Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject a SQL statement through the "… Imagicle Uc Suite 2021.summer.2+ Fix from $1,9502021-10-14 MEDIUM 5.4 CVE-2019-18207 In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field… Infobusiness after 4.4.1 Fix from $1,6002019-10-30 HIGH 8.8 CVE-2019-18204 Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution. Infobusiness after 4.4.1 Fix from $1,9502019-10-30 HIGH 8.8 CVE-2019-18206 A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload. Infobusiness after 4.4.1 Fix from $1,9502019-10-30 MEDIUM 6.1 CVE-2019-18205 Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did … Infobusiness after 4.4.1 Fix from $1,6002019-10-30 HIGH 7.5 CVE-2019-10257 Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restricted location (dot-dot-slash… Hr Portal after 2019-03-15 Fix from $1,9502019-06-19