ras-it.rs/research

Research

Common Vulnerabilities and Exposures (CVE)

Our team has discovered and responsibly disclosed a number of security vulnerabilities. Below is a selection of published CVEs with their associated severity scores.

CVE ID Description CVSS
CVE-2004-0790Microsoft Windows TCP/IP Stack denial of service7.5
CVE-2005-0688Microsoft Windows IPv6 Stack denial of service7.5
CVE-2008-6967Alt-N MDaemon cross site scripting4.3
CVE-2009-1484Gecad AXIGEN Mail Server cross site scripting4.3
CVE-2009-1801FreePBX reports.php cross site scripting4.3
CVE-2009-1802FreePBX cross site request forgery6.3
CVE-2009-1803FreePBX Error Message information disclosure5.3
CVE-2009-2455@Mail 'admin.php' Cross-Site Scripting Vulnerabilities4.3
CVE-2009-4038NCH Axon Virtual PBX cross site scripting4.3
CVE-2009-5087Geovision Digital Surveillance System directory traversal5.3
CVE-2018-2090LAMS < 3.1 - Cross-Site Scripting6.1
CVE-2019-0951Microsoft SharePoint Server CVE-2019-0951 Spoofing Vulnerability5.4
CVE-2022-25625Symantec/Broadcom Privileged Access Management (PAM) - Privilege Escalation Vulnerability8.2
CVE-2023-42784Fortinet FortiWeb - Web application firewall rules bypass5.5
CVE-2025-13746 ForumWP Stored Cross-Site Scripting 6.4

Responsible disclosure: All identified vulnerabilities were reported responsibly to the affected vendors or maintainers, in accordance with coordinated disclosure practices. Public disclosure was performed only after vendors had sufficient time to address the reported issues or release security updates.

All vulnerabilities were disclosed responsibly and assigned official CVE identifiers.