NA - CVE-2025-40656 - A SQL injection vulnerability has been found in...
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the cod parameter in...
NA - CVE-2025-40657 - A SQL injection vulnerability has been found in...
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform parameter in...
NA - CVE-2025-40658 - An Insecure Direct Object Reference (IDOR)...
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to...
NA - CVE-2025-40659 - An Insecure Direct Object Reference (IDOR)...
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to...
NA - CVE-2025-40660 - An Insecure Direct Object Reference (IDOR)...
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to...
NA - CVE-2025-40661 - An Insecure Direct Object Reference (IDOR)...
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to...
NA - CVE-2025-40662 - Absolute path disclosure vulnerability in DM...
Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents of webroot/file, if navigating to a non-existent file.
NA - CVE-2024-13089 - An OS command injection vulnerability within...
An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execute unauthorized arbitrary OS commands. Users with administrative privileges...
NA - CVE-2024-13090 - A privilege escalation vulnerability may enable...
A privilege escalation vulnerability may enable a service account to elevate its privileges. The sudo rules configured for a local service account were excessively permissive, potentially...
Medium - CVE-2025-41657 - Due to an undocumented active bluetooth stack...
Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerprinting is possible by an unauthenticated adjacent attacker.