CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
The Add page option in my little forum 2.4.12 allows XSS via the Title field.
Unified_communications_software, Better_together_over_ethernet_connector, C12, C16, C8, Vvx150, Vvx201, Vvx250, Vvx301, Vvx311
2018-12-17
N/A
6.1 MEDIUM
The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.
Unified_communications_software, Better_together_over_ethernet_connector, C12, C16, C8, Vvx150, Vvx201, Vvx250, Vvx301, Vvx311
2019-10-03
N/A
6.5 MEDIUM
The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authentication and subsequently record audio from the device microphone.
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?IntellectSystem= URI.
An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebApp/gcmsRefInsert?name=SUPP URI.
Matera Banco 1.0.0 is vulnerable to multiple reflected XSS, as demonstrated by the /contingency/web/index.jsp (aka home page) url parameter.
/contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file parameter.
Matera Banco 1.0.0 is vulnerable to path traversal (allowing access to system files outside the default application folder) via the /contingency/servlet/ServletFileDownload file parameter, related to /contingency/web/receiptQuery/receiptDisplay.jsp.
Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request.
