361,800
Total CVEs
26,223
Critical
85,816
High
1,626
CISA KEV
0
This Week
5 results · Page 1/1
Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbitrary code via the query parameter to the /CMD0/xml_modes.xml endpoint
An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information about whether a user exists on a system.
innovaphone
An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker may be able to access the administration panel
innovaphone
AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload.
innovaphone