NA - CVE-2024-56908 - In Perfex Crm < 3.2.1, an authenticated...
In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with...
NA - CVE-2025-22960 - A session hijacking vulnerability exists in the...
A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated attackers can access exposed log files...
NA - CVE-2025-22961 - A critical information disclosure vulnerability...
A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters due to Incorrect Access Control (CWE-284). Unauthenticated...
NA - CVE-2025-22962 - A critical remote code execution (RCE)...
A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters when debugging mode is enabled. An attacker with a valid...
NA - CVE-2020-3432 - A vulnerability in the uninstaller component of...
A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem....
NA - CVE-2023-20508 - Improper access control in the ASP could allow...
Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled by the attacker, potentially leading to loss of...