trustcves
13 exploits
Active since Mar 2023
Logbuch <8.2.2286, <9.0.2401 - SQL Injection
Sage DPW < 2024_12_000 - Stored Cross-Site Scripting via Kurstitel and Kurzinfo Input Fields
CVSS 5.4
Sage DPW <2024_12_001 - Incorrect Access Control
CVSS 8.1
Stimulsoft Dashboard.JS < 2024.1.2 - Remote Code Execution via Search Bar Component
CVSS 6.1
stimulsoft dashboards.js < 2024.1.2 - Cross-Site Scripting via ReportName Field
CVSS 5.4
Stimulsoft Dashboard.JS < 2024.1.2 - Path Traversal via Save Function FileName Parameter
CVSS 9.8
Safe FME Server < 2022.2.5 - Authenticated Path Traversal and Arbitrary File Write via Network Resource Connection
CVSS 8.1
evasys <8.2.2286 & <9.0.2401 - Info Disclosure
CVSS 8.1
Stimulsoft Designer and Viewer - Remote Code Execution via Report Variable Injection
CVSS 9.8
Stimulsoft Designer 2023.1.3 - Server-Side Request Forgery via External Resource Embedding
CVSS 7.5
Stimulsoft Designer 2023.1.4-2023.1.5 - Cleartext Storage of Sensitive Information in Connection String
CVSS 5.5
evasys < 8.2 Build 2286 and 9.x < 9.0 Build 2401 - Authenticated Stored Cross-Site Scripting via User Profile Parameters
CVSS 5.4
Stimulsoft Designer (Web) 2023.1.3 - Local File Inclusion
CVSS 7.5