NA - CVE-2024-44313 - TastyIgniter 3.7.6 contains an Incorrect Access...
TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing...
NA - CVE-2024-44314 - TastyIgniter 3.7.6 contains an Incorrect Access...
TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the...
Medium - CVE-2024-49822 - IBM QRadar Advisor 1.0.0 through 2.6.5 is...
IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially...
NA - CVE-2025-25585 - Incorrect access control in the component...
Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.
NA - CVE-2025-30107 - On IROAD V9 devices, Managing Settings and...
On IROAD V9 devices, Managing Settings and Obtaining Sensitive Data and Sabotaging the Car Battery can be performed by unauthorized parties. A vulnerability in the dashcam's configuration...
NA - CVE-2025-30109 - In the IROAD APK 5.2.5, there are Hardcoded...
In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded credentials that allow an attacker on the local...
NA - CVE-2025-30110 - On IROAD X5 devices, a Bypass of Device Pairing...
On IROAD X5 devices, a Bypass of Device Pairing can occur via MAC Address Spoofing. The dashcam's pairing mechanism relies solely on MAC address verification, allowing an attacker to bypass...