trms records
5 published records for vendor trms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-269 Improper Privilege Management1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-798 Use of Hard-coded Credentials1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-13020No exploit | The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF.trms · tightrope media carousel · CWE-918 | Critical10.0 | — | 1.1% | Aug 26, 2019 |
36Monitor | CVE-2018-18930No exploit | The Tightrope Media Carousel digital signage product 7.0.4.104 contains an arbitrary file upload vulnerability in the Manage Bulletins/Uploatrms · carousel digital signage · CWE-434 | High8.8 | — | 2.8% | Oct 29, 2019 |
35Monitor | CVE-2018-18931No exploit | An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104.trms · carousel digital signage · CWE-269 | High8.8 | — | 1.6% | Oct 29, 2019 |
35Monitor | CVE-2018-18929No exploit | The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and passwortrms · seneca hdn firmware · CWE-798 | High8.8 | — | 1.1% | Oct 29, 2019 |
24Monitor | CVE-2018-14573No exploit | A Local File Inclusion (LFI) vulnerability exists in the Web Interface API of TightRope Media Carousel Digital Signage before 7.3.5.trms · tightrope media carousel digital signage · CWE-22 | Medium5.5 | — | 6.4% | Jul 23, 2018 |
- CVE-2019-1302040Plan
The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF.
CriticalCVSS 10.0No exploitEPSS 1%trms · tightrope media carouselAug 26, 2019
- CVE-2018-1893036Monitor
The Tightrope Media Carousel digital signage product 7.0.4.104 contains an arbitrary file upload vulnerability in the Manage Bulletins/Uploa
HighCVSS 8.8No exploitEPSS 3%trms · carousel digital signageOct 29, 2019
- CVE-2018-1893135Monitor
An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104.
HighCVSS 8.8No exploitEPSS 2%trms · carousel digital signageOct 29, 2019
- CVE-2018-1892935Monitor
The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and passwor
HighCVSS 8.8No exploitEPSS 1%trms · seneca hdn firmwareOct 29, 2019
- CVE-2018-1457324Monitor
A Local File Inclusion (LFI) vulnerability exists in the Web Interface API of TightRope Media Carousel Digital Signage before 7.3.5.
MediumCVSS 5.5No exploitEPSS 6%trms · tightrope media carousel digital signageJul 23, 2018