Search: "digital"

1129 CVEs found

Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can ...

Published: 2025-12-10
Products: 1
Vendors:
eibiz

Eibiz i-Media Server Digital Signage 3.8.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through AMF-encoded object manipulation. Attacker...

Published: 2025-12-10
Products: 1
Vendors:
eibiz

EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object ref...

Published: 2025-12-10
Products: 1
Vendors:
eibiz

QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. ...

Published: 2025-12-10
Products: 1
Vendors:
howfor
CVE-2020-36897
9.8 CRITICAL

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to upload malicious ASPX scripts. Attackers can exploit...

Published: 2025-12-10
Products: 1
Vendors:
howfor
CVE-2020-36898
9.1 CRITICAL

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers to delete files without authentication. Attackers ca...

Published: 2025-12-10
Products: 1
Vendors:
howfor

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' paramet...

Published: 2025-12-10
Products: 1
Vendors:
howfor

All-Dynamics Digital Signage System 2.0.2 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craf...

Published: 2025-12-10
Products: 1
Vendors:
all-dynamics

UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers ca...

Published: 2025-12-10
Products: 2
Vendors:
medivision
CVE-2020-36902
9.8 CRITICAL

UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET...

Published: 2025-12-10
Products: 2
Vendors:
medivision
CVE-2025-55311
6.5 MEDIUM

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's...

Published: 2025-12-11
Products: 12
Vendors:
microsoft apple foxit

Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the dig...

Published: 2025-12-11
Products: 16
Vendors:
microsoft apple foxit
CVE-2025-59803
5.3 MEDIUM

Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF document that execute during the signing process. When a s...

Published: 2025-12-11
Products: 16
Vendors:
microsoft apple foxit
CVE-2025-49919
5.8 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Retrieve Embedded Sensitive Data.This issue affects eRoom: from n/a through <= 1.5...

Published: 2025-12-18
Products: 0

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixe...

Published: 2025-12-18
Products: 1
Vendors:
imagemagick

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinafter referred to as "keypad function") of Mitsubishi ...

Published: 2025-12-19
Products: 0
CVE-2025-66522
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sanitize or encode the ...

Published: 2025-12-19
Products: 1
Vendors:
foxit
CVE-2019-25255
4.3 MEDIUM

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can exploit t...

Published: 2025-12-24
Products: 0
CVE-2019-25256
6.5 MEDIUM

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers to access arbitrary system files through unvalidated 'ID' parameters. Atta...

Published: 2025-12-24
Products: 0
CVE-2025-67013
6.5 MEDIUM

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin...

Published: 2025-12-26
Products: 54
Vendors:
etlsystems