Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Telemessage CRITICAL 9.8
CVE-2025-48929

The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time)…

Fix: after 2025-05-05
Fix from $2,300 2025-05-28
Telemessage MEDIUM 5.5
CVE-2025-48931

The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables)…

Fix: after 2025-05-05
Fix from $1,600 2025-05-28
Telemessage MEDIUM 5.3
CVE-2025-48930

The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversa…

Fix: after 2025-05-05
Fix from $1,600 2025-05-28
Telemessage HIGH 7.5
CVE-2025-48925

The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the auth…

Fix: after 2025-05-05
Fix from $1,950 2025-05-28
Telemessage HIGH 7.5
CVE-2025-48926

The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numb…

Fix: after 2025-05-05
Fix from $1,950 2025-05-28
Telemessage MEDIUM 5.3
CVE-2025-48927 KEVEPSS 9%

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the…

Mitigation only
Fix from $1,600 2025-05-28
Telemessage HIGH 7.5
CVE-2025-47730

The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app…

Fix: after 2025-05-05
Fix from $1,950 2025-05-08