NA - CVE-2025-52920 - Innoshop through 0.4.1 allows Insecure Direct...
Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful...
NA - CVE-2025-52921 - In Innoshop through 0.4.1, an authenticated...
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then...
NA - CVE-2025-52922 - Innoshop through 0.4.1 allows directory...
Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure...
NA - CVE-2025-6512 - On a client with a non-admin user, a script can...
On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights.
NA - CVE-2025-2171 - Aviatrix Controller versions prior to 7.1.4208,...
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN
NA - CVE-2025-2172 - Aviatrix Controller versions prior to 7.1.4208,...
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special...
NA - CVE-2023-47297 - A settings manipulation vulnerability in NCR...
A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations.