Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

I Mcs Nfv MEDIUM 6.1
CVE-2024-28803

Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary we…

No fix yet
Fix from $1,600 2025-03-13
Embrace HIGH 8.8
CVE-2024-31842

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The quer…

Mitigation only
Fix from $1,950 2024-08-20
I Mcs Nfv HIGH 7.5
CVE-2024-28806

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path.

Mitigation only
Fix from $1,950 2024-07-29
I Mcs Nfv CRITICAL 9.1
CVE-2024-28805

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

No fix yet
Fix from $2,300 2024-07-29
I Mcs Nfv HIGH 7.1
CVE-2024-28804

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Stored Cross-site scripting (XSS) can occur via POST.

No fix yet
Fix from $1,950 2024-07-29
Embrace MEDIUM 6.1
CVE-2024-31847

An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and unauthenticated remote a…

No fix yet
Fix from $1,600 2024-05-21
Embrace MEDIUM 5.3
CVE-2024-31844

An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a disclosure o…

No fix yet
Fix from $1,600 2024-05-21
Embrace MEDIUM 5.3
CVE-2024-31845

An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web …

No fix yet
Fix from $1,600 2024-05-21
Embrace MEDIUM 6.5
CVE-2024-31840

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is a…

No fix yet
Fix from $1,600 2024-05-21
Embrace HIGH 7.5
CVE-2024-31841

An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbi…

No fix yet
Fix from $1,950 2024-04-19
Embrace HIGH 7.5
CVE-2024-31846

An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unautho…

No fix yet
Fix from $1,950 2024-04-19
Netmatch S Ci CRITICAL 9.1
CVE-2022-39811

Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not ve…

No fix yet
Fix from $2,300 2023-01-27
Netmatch S Ci HIGH 7.5
CVE-2022-39812

Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to …

No fix yet
Fix from $1,950 2023-01-27
Netmatch S Ci MEDIUM 6.1
CVE-2022-39813

Italtel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via the j_username parameter, or …

No fix yet
Fix from $1,600 2023-01-27