|
1171
|
7.8 |
HIGH
Local
|
genetec
|
genetec_update_service
|
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.
|
CWE-276
Incorrect Default Permissions
|
CVE-2025-1789
|
2026-04-27 03:49 |
2026-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1172
|
7.8 |
HIGH
Local
|
genetec
|
genetec_update_service
|
Escalada de privilegios local en el Servicio de Actualización de Genetec. Un usuario de Windows autenticado y con pocos privilegios podría explotar esta vulnerabilidad para obtener privilegios elevad…
|
CWE-276
Incorrect Default Permissions
|
CVE-2025-1789
|
2026-04-27 03:49 |
2026-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1173
|
4.2 |
MEDIUM
Local
|
genetec
|
genetec_update_service
|
Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows user could exploit this vulnerability to gain elevated privil…
|
CWE-346
Origin Validation Error
|
CVE-2025-1787
|
2026-04-27 03:49 |
2026-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1174
|
4.2 |
MEDIUM
Local
|
genetec
|
genetec_update_service
|
El administrador local podría filtrar información de la página web de configuración del Servicio de Actualización de Genetec. Un usuario de Windows autenticado y con privilegios de administrador podr…
|
CWE-346
Origin Validation Error
|
CVE-2025-1787
|
2026-04-27 03:49 |
2026-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1175
|
8.8 |
HIGH
Network
|
mrsilaz
|
mfa_mail
|
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-4208
|
2026-04-26 03:43 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1176
|
8.8 |
HIGH
Network
|
mrsilaz
|
mfa_mail
|
La extensión no restablece correctamente el código MFA generado después de una autenticación exitosa. Esto conduce a una posible omisión de MFA para futuros intentos de inicio de sesión al proporcion…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-4208
|
2026-04-26 03:43 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1177
|
4.3 |
MEDIUM
Network
|
ayacoo
|
redirect_tab
|
The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of redirect records when editing a page.
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2026-4202
|
2026-04-26 03:40 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1178
|
4.3 |
MEDIUM
Network
|
ayacoo
|
redirect_tab
|
La extensión falla al verificar si un usuario autenticado tiene permisos para acceder a las redirecciones, resultando en la exposición de registros de redirección al editar una página.
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2026-4202
|
2026-04-26 03:40 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1179
|
8.8 |
HIGH
Network
|
cps-it
|
mailqueue
|
The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active explo…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-1323
|
2026-04-26 03:37 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1180
|
8.8 |
HIGH
Network
|
cps-it
|
mailqueue
|
La extensión no define correctamente las clases permitidas utilizadas al deserializar metadatos de fallo de transporte. Un atacante puede explotar esto para ejecutar código serializado no confiable. …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-1323
|
2026-04-26 03:37 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|