Products: 1
    Vulnerabilities: 8
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    6
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-48931

    The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables) with low computational effort.

    Last Modified: Oct 03, 2025
    Published: May 28, 2025

    CVE-2025-48928

    The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.

    Last Modified: Feb 26, 2026
    Published: May 28, 2025

    CVE-2025-48927

    The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.

    Last Modified: Feb 26, 2026
    Published: May 28, 2025

    CVE-2025-48925

    The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.

    Last Modified: Oct 22, 2025
    Published: May 28, 2025

    CVE-2025-48926

    The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

    Last Modified: Oct 22, 2025
    Published: May 28, 2025
    Items Per Page
    Smarsh Vulnerabilities & Security CVEs | CVE-DB