← Back

Intesync

intesync

13 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Solismed
solismed
Miniweb
miniweb

CVEs (13)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted.
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intesync Solismed 3.3sp allows Insecure File Upload.
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Intesync Solismed 3.3sp has XSS.
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Intesync Solismed 3.3sp has CSRF.
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intesync Solismed 3.3sp has SQL Injection.
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intesync Solismed 3.3sp has Incorrect Access Control.
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Intesync Solismed 3.3sp allows Clickjacking.
1Intesync
1Miniweb
Apr 23, 2026
Jan 4, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
1Intesync
1Miniweb
Apr 23, 2026
Jan 4, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to index.php.
1Intesync
1Miniweb
Apr 23, 2026
Sep 25, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter and the (2) PATH_INFO.
1Intesync
1Miniweb
Apr 23, 2026
Sep 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter.