Skip to main content

Vendor archive

assaabloy CVEs

Beta · best-effort

19 CVEs tagged to vendor assaabloy5 Critical, 4 High, 8 Medium, 2 Low, 0 Unrated.

CVE-2025-49853

Published Jun 24, 2025

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL sy…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-49852

Published Jun 24, 2025

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49851

Published Jun 24, 2025

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and ga…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2125

Published Mar 9, 2025

A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects unknown code of the file /v2/report.svc/comprovante_marcacao…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2023-4392

Published Aug 17, 2023

A vulnerability was found in Control iD Gerencia Web 1.30 and classified as problematic. Affected by this issue is some unknown functionality of the component Cookie Handler. The…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-33367

Published Aug 5, 2023

A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-33371

Published Aug 3, 2023

Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and b…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-33370

Published Aug 3, 2023

An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDSecure to fault and crash, causing a den…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33369

Published Aug 3, 2023

A path traversal vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to delete arbitrary files on IDSecure filesystem, causing a denial of service.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-33368

Published Aug 3, 2023

Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2044

Published Apr 14, 2023

A vulnerability has been found in Control iD iDSecure 4.7.29.1 and classified as problematic. This vulnerability affects unknown code of the component Dispositivos Page. The manip…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-2043

Published Apr 14, 2023

A vulnerability, which was classified as problematic, was found in Control iD RHiD 23.3.19.0. This affects an unknown part of the file /v2/customerdb/operator.svc/a of the compone…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1