A vulnerability was found in Quatuor Evaluación de Desempeño. It has been declared as critical. Impacted is an unknown function of the file /evaluacion_hca_ver_auto.asp. The manipulation of the argument Id_usuario/Id_evaluacion results in sql injection.
This vulnerability is reported as CVE-2026-1479. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Quatuor Evaluación de Desempeño. It has been rated as critical. The affected element is an unknown function of the file /evaluacion_objetivos_anyo_sig_evalua.aspx. This manipulation of the argument Id_usuario causes sql injection.
This vulnerability appears as CVE-2026-1480. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as critical has been discovered in Quatuor Evaluación de Desempeño. The impacted element is an unknown function of the file /evaluacion_objetivos_anyo_sig_ver_auto.aspx. Such manipulation of the argument Id_usuario leads to sql injection.
This vulnerability is traded as CVE-2026-1481. The attack may be launched remotely. There is no exploit available.
A vulnerability identified as critical has been detected in Quatuor Evaluación de Desempeño. This affects an unknown function of the file /evaluacion_objetivos_evalua_definido.aspx. Performing a manipulation of the argument Id_evaluacion results in sql injection.
This vulnerability is known as CVE-2026-1482. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability labeled as critical has been found in Quatuor Evaluación de Desempeño. This impacts an unknown function of the file /evaluacion_objetivos_ver_auto.aspx. Executing a manipulation of the argument Id_usuario can lead to sql injection.
This vulnerability is handled as CVE-2026-1483. The attack can be executed remotely. There is not any exploit available.
A vulnerability classified as problematic has been found in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise 10.4.18. The affected element is an unknown function of the component Configuration Restore Handler. This manipulation causes denial of service.
This vulnerability is registered as CVE-2025-59895. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability labeled as problematic has been found in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise 10.4.18. The affected element is an unknown function of the file /edit_command. The manipulation of the argument source_dir/dest_dir results in cross site scripting.
This vulnerability is identified as CVE-2025-59897. The attack can be executed remotely. There is not any exploit available.
A vulnerability marked as problematic has been reported in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise 10.4.18. The impacted element is an unknown function of the file /setup_login of the component POST Request Handler. This manipulation of the argument username/password/cpassword causes cross-site request forgery.
This vulnerability is tracked as CVE-2025-59891. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability described as problematic has been identified in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise 10.4.18. This affects an unknown function of the file /delete_command of the component POST Request Handler. Such manipulation of the argument cid leads to cross-site request forgery.
This vulnerability is listed as CVE-2025-59892. The attack may be performed from remote. There is no available exploit.
A vulnerability classified as problematic has been found in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise 10.4.18. This impacts an unknown function of the file /rename_command of the component POST Request Handler. Performing a manipulation of the argument command_name results in cross-site request forgery.
This vulnerability is cataloged as CVE-2025-59893. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise 10.4.18. Affected is an unknown function of the file /delete_all_commands of the component POST Request Handler. Executing a manipulation can lead to cross-site request forgery.
This vulnerability is registered as CVE-2025-59894. It is possible to launch the attack remotely. No exploit is available.
A vulnerability, which was classified as problematic, has been found in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise 10.4.18. Affected by this vulnerability is an unknown functionality of the file /add_command. The manipulation of the argument command_name leads to cross site scripting.
This vulnerability is documented as CVE-2025-59896. The attack can be initiated remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, was found in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise 10.4.18. Affected by this issue is some unknown functionality of the file /server_options. The manipulation of the argument tasks_logs_dir/errors_logs_dir/error_notifications_address/status_notifications_address/status_reports_address results in cross site scripting.
This vulnerability is reported as CVE-2025-59899. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise 10.4.18 and classified as problematic. This vulnerability affects unknown code of the file /server_options. Such manipulation of the argument tasks_logs_dir/errors_logs_dir/error_notifications_address/status_notifications_address/status_reports_address leads to cross site scripting.
This vulnerability is traded as CVE-2025-59900. The attack may be launched remotely. There is no exploit available.