Show filters
77 Total Results
Displaying 41-50 of 77
Sort by:
Attacker Value
Unknown

CVE-2021-44554

Disclosure Date: December 20, 2021 (last updated February 23, 2025)
Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker can determine if a username exists thanks to the message returned; it can be presented in different languages according to the configuration of VirtualUI. Common users are administrator, admin, guest and krgtbt.
Attacker Value
Unknown

CVE-2021-45092

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.
Attacker Value
Unknown

CVE-2021-44848

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.
Attacker Value
Unknown

CVE-2021-31925

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative web interface.
Attacker Value
Unknown

CVE-2020-25868

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote attacker can trigger a software abort (temporary loss of service).
Attacker Value
Unknown

CVE-2021-27651

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
Attacker Value
Unknown

CVE-2021-27653

Disclosure Date: March 30, 2021 (last updated February 22, 2025)
Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.
Attacker Value
Unknown

CVE-2019-7178

Disclosure Date: September 25, 2020 (last updated February 22, 2025)
Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.
Attacker Value
Unknown

CVE-2017-17477

Disclosure Date: September 25, 2020 (last updated February 22, 2025)
Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.
Attacker Value
Unknown

CVE-2020-13387

Disclosure Date: September 25, 2020 (last updated February 22, 2025)
Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323.