OpenBiz Cubi Lite 3
Description
OpenBiz Cubi Lite 3
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Search and filter 22413 vulnerabilities with AI analyst insights
OpenBiz Cubi Lite 3
OpenBiz Cubi Lite 3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
qdPM 9
qdPM 9
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
KomSeo Cart 1
KomSeo Cart 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
ASP
ASP
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Library CMS 1
Library CMS 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Online Store System CMS 1
Online Store System CMS 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
SAT CFDI 3
SAT CFDI 3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OOP CMS BLOG 1
OOP CMS BLOG 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
PlayJoom 0
PlayJoom 0
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
ServerZilla 1
ServerZilla 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Wecodex Hotel CMS 1
Wecodex Hotel CMS 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Nominas 0
Nominas 0
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Mongoose Web Server 6
Mongoose Web Server 6
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
GPS Tracking System 2
GPS Tracking System 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Facturation System 1
Facturation System 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Data Center Audit 2
Data Center Audit 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Webiness Inventory 2
Webiness Inventory 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Tina4 Stack 1
Tina4 Stack 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Wecodex Restaurant CMS 1
Wecodex Restaurant CMS 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Shipping System CMS 1
Shipping System CMS 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Silurus Classifieds Script 2
Silurus Classifieds Script 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Musicco 2
Musicco 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Maitra 1
Maitra 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Gumbo CMS 0
Gumbo CMS 0
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Easyndexer 1
Easyndexer 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Alive Parish 2
Alive Parish 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Alienor Web Libre 2
Alienor Web Libre 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Rmedia SMS 1
Rmedia SMS 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Pedidos 1
Pedidos 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code thro...
EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter
Apply vendor patches immediately. Review database access controls and enable query logging.
DoceboLMS 1
DoceboLMS 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
AMPPS 2
AMPPS 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Net-Billetterie 2
Net-Billetterie 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Meneame English Pligg 5
Meneame English Pligg 5
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Galaxy Forces MMORPG 0
Galaxy Forces MMORPG 0
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
EverSync 0
EverSync 0
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
BitZoom 1
BitZoom 1
---METADATA---
VENDOR: Zoom
PRODUCT: BitZoom
AFFECTED_VERSIONS: BitZoom 1; See vendor advisory for other versions
---END_METADATA---
Description Summary:
A late-disclosure vulnerability in Zoom BitZoom 1 presents a significant security risk, potentially allowing for unauthorized access or execution within the application environment.
Executive Summary:
Zoom BitZoom 1 is subject to a high-severity vulnerability that could be exploited to compromise application security, necessitating immediate remediation despite its late disclosure.
Vulnerability Details
CVE-ID: CVE-2018-25163
Affected Software: Zoom BitZoom
Affected Versions: BitZoom 1
Vulnerability: This vulnerability, while originating in 2018, has been recently disclosed and affects BitZoom 1. The high CVSS score suggests a critical flaw in input validation or session management that could be exploited by an attacker to gain elevated privileges or execute unauthorized commands.
Business Impact
The impact of this vulnerability includes potential data breaches and unauthorized control over communication tools. With a CVSS score of 8.2, this is a High-severity issue; the late disclosure means that systems may have been vulnerable for years, increasing the risk that historical compromises may have occurred.
Remediation Plan
Immediate Action: Upgrade BitZoom to the most recent version or apply the vendor-provided legacy patch to mitigate the identified risk.
Proactive Monitoring: Conduct a retrospective security audit of logs dating back to the initial deployment of BitZoom 1 to identify any historical signs of unauthorized access.
Compensating Controls: Isolate the BitZoom application within a segmented network and enforce multi-factor authentication (MFA) for all users to limit the potential attack surface.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 8, 2026, there is no public information indicating active exploitation of this vulnerability. The late disclosure (2018 ID) suggests this may have been discovered during a legacy code review or audit.
Analyst Recommendation
Despite the age of the CVE identifier, the CVSS score of 8.2 demands urgent attention. Organizations still utilizing BitZoom 1 must apply updates immediately or transition to a supported version to ensure the security of their communications infrastructure.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Warranty Tracking System 11
Warranty Tracking System 11
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated atta...
Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.
---METADATA---
VENDOR: Epross
PRODUCT: AVCON6
AFFECTED_VERSIONS: * (All versions)
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
The Epross AVCON6 platform contains an OGNL injection vulnerability in the login.action endpoint, allowing unauthenticated attackers to execute arbitrary system commands as root.
Executive Summary:
An unauthenticated remote code execution vulnerability in the Epross AVCON6 platform allows attackers to execute arbitrary commands with root privileges via OGNL injection.
Vulnerability Details
CVE-ID: CVE-2018-25159
Affected Software: Epross AVCON6 systems management platform
Affected Versions: All versions
Vulnerability: The application is vulnerable to OGNL injection (CWE-1334) through the redirect parameter in the login.action endpoint. This allows unauthenticated attackers to instantiate ProcessBuilder objects and execute system-level commands with root privileges.
Business Impact
This vulnerability grants an attacker full control over the affected system with the highest level of privilege. A successful exploit could lead to complete data exfiltration, system destruction, or the deployment of persistent malware, causing severe reputational and operational damage.
Remediation Plan
Immediate Action: Apply the latest security updates provided by the vendor. If no patch is available, disable the affected management platform functionality.
Proactive Monitoring: Inspect server logs for anomalous requests containing OGNL patterns or attempts to manipulate the redirect parameter.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block OGNL expression patterns and suspicious redirect parameters targeted at the login endpoint.
Exploitation Status
Public Exploit Available: Yes — a public exploit is available via ExploitDB (47379).
Analyst Notes: As of March 11, 2026, there is no confirmed active exploitation in the wild; however, per CISA's SSVC assessment a proof-of-concept exists, so exploitation risk should be treated as credible. The presence of a public exploit in ExploitDB significantly lowers the barrier to entry for attackers.
Analyst Recommendation
The combination of unauthenticated access, root-level command execution, and the availability of a public exploit makes this a high-priority risk. Organizations must ensure that the management interface is not exposed to the internet and apply vendor-supplied patches immediately upon availability.
Update Epross Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
Chamilo LMS 1
Chamilo LMS 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attacker...
GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.
---METADATA---
VENDOR: GNU
PRODUCT: Barcode
AFFECTED_VERSIONS: 0.99
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
GNU Barcode 0.99 contains a buffer overflow vulnerability in the code 93 encoding process, which may allow attackers to trigger memory corruption and potentially execute arbitrary code.
Executive Summary:
A critical buffer overflow vulnerability in GNU Barcode 0.99 allows for potential arbitrary code execution, posing a severe risk to system integrity and stability.
Vulnerability Details
CVE-ID: CVE-2018-25154
Affected Software: GNU Barcode
Affected Versions: 0.99
Vulnerability: This is a buffer overflow vulnerability occurring during the code 93 encoding process. It stems from boundary errors during input file processing, which can be leveraged by an attacker to induce memory corruption.
Business Impact
With a CVSS score of 9.8, this vulnerability presents a high risk for remote code execution (RCE). Successful exploitation could allow an attacker to gain control over the host system, leading to unauthorized data access, system disruption, or the potential for lateral movement within the network.
Remediation Plan
Immediate Action: Update GNU Barcode to the latest available version to patch the identified memory corruption flaw.
Proactive Monitoring: Monitor system logs for crashes related to barcode processing applications or unexpected process terminations.
Compensating Controls: Ensure that applications utilizing GNU Barcode are running with the least privilege necessary and are sandboxed to limit the impact of a potential code execution event.
Exploitation Status
Public Exploit Available: Not specified
Analyst Notes: As of Dec 24, 2025, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
The risk of arbitrary code execution necessitates immediate attention. Users of GNU Barcode should verify their current version and apply the vendor-provided security update as soon as possible to mitigate the risk of system compromise.
Update GNU Barcode Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
GNU Barcode 0
GNU Barcode 0
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Microhard Systems IPn4G 1
Microhard Systems IPn4G 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Microhard Systems IPn4G 1
Microhard Systems IPn4G 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Microhard Systems IPn4G 1
Microhard Systems IPn4G 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import s...
NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.
---METADATA---
VENDOR: NovaRad
PRODUCT: NovaPACS Diagnostics Viewer
AFFECTED_VERSIONS: 8.5.19.75
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in the XML preference import settings.
Executive Summary:
An unauthenticated XXE injection vulnerability in NovaRad NovaPACS Diagnostics Viewer allows attackers to retrieve sensitive system files, posing a critical risk to data confidentiality.
Vulnerability Details
CVE-ID: CVE-2018-25142
Affected Software: NovaRad NovaPACS Diagnostics Viewer
Affected Versions: 8.5.19.75
Vulnerability: This is an XML External Entity (XXE) injection vulnerability located in the XML preference import settings. It allows an unauthenticated attacker to inject malicious DTD parameter entities into an XML file to retrieve arbitrary files from the host system via out-of-band communication.
Business Impact
The CVSS score of 9.8 underscores the severity of this vulnerability, as it allows for the unauthorized exfiltration of sensitive system files. In a clinical or diagnostic environment, this could lead to the exposure of Protected Health Information (PHI) or system configuration data, resulting in severe regulatory and operational consequences.
Remediation Plan
Immediate Action: Update the NovaRad NovaPACS Diagnostics Viewer to the latest version that mitigates XXE injection risks.
Proactive Monitoring: Monitor for anomalous outbound network traffic from the PACS server, which could indicate exfiltration attempts via out-of-band channels.
Compensating Controls: Implement strict file validation for any XML inputs and disable the processing of external entities in the XML parser configuration if a patch cannot be immediately applied.
Exploitation Status
Public Exploit Available: Not specified
Analyst Notes: As of Dec 24, 2025, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Given the potential for unauthorized file access, this vulnerability must be treated with extreme urgency. Administrators should update the software immediately and restrict access to the XML import features to trusted users only until the patch is successfully deployed.
Update NovaRad NovaPACS Diagnostics Viewer Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials
FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials
Executive Summary:
A high-severity vulnerability exists in multiple FLIR thermal traffic cameras, identified as CVE-2018-25141. This flaw allows unauthenticated remote attackers to bypass security controls and gain direct access to live video streams. Exploitation of this vulnerability could lead to a significant breach of confidentiality, enabling unauthorized surveillance of sensitive areas monitored by these cameras.
Vulnerability Details
CVE-ID: CVE-2018-25141
Affected Software: FLIR Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The affected FLIR cameras contain an improper access control vulnerability. A specific endpoint or URL path for the live video stream does not enforce authentication, allowing anyone with network access to the device to view the feed. An attacker can exploit this by sending a crafted HTTP request directly to the vulnerable endpoint, completely bypassing the need for a username and password.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 7.5. The primary business impact is a severe loss of confidentiality. Unauthorized access to live video feeds from traffic or security cameras can expose sensitive operational data, enable industrial espionage, facilitate the planning of physical security breaches, or lead to significant privacy violations. For organizations managing critical infrastructure or secure facilities, this could allow adversaries to monitor personnel movements, security patrol patterns, and daily operations, posing a direct risk to physical security and safety.
Remediation Plan
Immediate Action: Apply the security updates provided by FLIR to all affected devices immediately. Prior to and after patching, review camera access logs for any unusual or unauthorized connections, particularly from external IP addresses.
Proactive Monitoring: Implement network monitoring to detect anomalous traffic patterns to and from the affected cameras. Specifically, look for a high volume of requests to video streaming ports or direct connections from IP addresses not associated with authorized management systems or viewers. Configure alerts for repeated access attempts or connections from unexpected geographic locations.
Compensating Controls: If immediate patching is not feasible, implement network segmentation to isolate the cameras from the public internet and other internal corporate networks. Use a firewall or Access Control Lists (ACLs) to strictly limit access to the cameras' management and video ports, allowing connections only from a trusted IP range or a dedicated jump host/management station.
Exploitation Status
Public Exploit Available: true
Analyst Notes: As of December 26, 2025, while this vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, the method for exploitation is publicly documented. The simplicity of the exploit (often just requiring knowledge of a specific URL) means that attackers can easily scan the internet for exposed devices using tools like Shodan and automate exploitation at scale.
Analyst Recommendation
Given the high severity (CVSS 7.5) and the public availability of exploit information, immediate action is required. Organizations must prioritize the deployment of vendor-supplied patches to all affected FLIR cameras. If patching is delayed, the implementation of compensating controls, such as network isolation and strict firewall rules, is critical to mitigate the immediate risk of unauthorized surveillance. The lack of a CISA KEV listing should not diminish the urgency, as the low complexity of this attack makes vulnerable, internet-exposed devices prime targets for opportunistic threat actors.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to b...
FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
FLIR AX8 Thermal Camera 1
FLIR AX8 Thermal Camera 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
FLIR AX8 Thermal Camera 1
FLIR AX8 Thermal Camera 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Tina4
PRODUCT: Tina4 Stack
AFFECTED_VERSIONS: Tina4 Stack 1; See vendor advisory
---END_METADATA---
Description Summary:
A high-severity vulnerability has been disclosed in the Tina4 Stack 1, which could allow attackers to compromise web applications built on this framework.
Executive Summary:
The Tina4 Stack 1 framework contains a significant vulnerability that puts all dependent web applications at risk of unauthorized access or data manipulation.
Vulnerability Details
CVE-ID: CVE-2018-25187
Affected Software: Tina4 Stack
Affected Versions: Tina4 Stack 1
Vulnerability: This vulnerability affects the Tina4 Stack framework. Given the CVSS score of 8.2, it likely involves a flaw in the routing engine or database abstraction layer, potentially allowing for unauthenticated remote code execution or SQL injection depending on how the stack handles external inputs.
Business Impact
A successful exploit could lead to the complete takeover of any web application utilizing the Tina4 Stack. This poses a severe risk to business continuity and data integrity, as reflected by the 8.2 CVSS score. Organizations may face significant reputational damage if customer data is leaked through this framework flaw.
Remediation Plan
Immediate Action: Developers must update the Tina4 Stack to the latest secure version and rebuild/redeploy all dependent applications to incorporate the fix.
Proactive Monitoring: Implement enhanced logging for the web server and monitor for unusual database queries or unexpected file system changes.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules specifically designed to block common framework-level exploits and restrict access to administrative endpoints.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 8, 2026, there is no public information indicating active exploitation. This late disclosure highlights the need for ongoing dependency scanning and software composition analysis (SCA) to identify hidden risks in legacy stacks.
Analyst Recommendation
The 8.2 CVSS score indicates a high level of risk that cannot be ignored. We recommend an immediate audit of all applications using the Tina4 Stack and the immediate application of security patches to protect against potential exploitation.