Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-25232 | Softros LAN Messenger 9.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long strin Softros LAN Messenger 9.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the custom log files location field. Attackers can input a buffer of 2000 characters in the Log Files Location custom path parameter to trigger a crash when the OK button is clicked. NVD description · AI analysis pending | 6.8 | <1% | PoC |
| — | |
| CVE-2022-48085 | Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter. Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-40434 | Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page. Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2022-32407 | Softr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the Create A New Account module. Softr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the Create A New Account module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-25375 | Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field, Mobile field, Place of Birth field, Web Site field, VAT Number field, Last Name field, Fax field, Email field, and Skype field. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2018-7658 | NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exactly 11 by NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exactly 11 bytes. NVD description · AI analysis pending | 7.5 | 39% | PoC ×2 |
| — |