Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2020-18327 Cross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter in the alfresco/s/admin/admin-… Alfresco No fix yet Fix from $1,6002022-03-04 HIGH 8.8 CVE-2021-41790 An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded o… Alfresco Content Services after 7.0.1.2 Fix from $1,9502021-10-21 MEDIUM 5.4 CVE-2021-41791 An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An evasion of the XSS filter for H… Community Share after 7.0 Fix from $1,6002021-10-21 MEDIUM 5.3 CVE-2021-41792 An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A… Alfresco Content Services after 6.2.2.18 Fix from $1,6002021-10-21 CRITICAL 9.8 CVE-2020-15181 The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the sy… Reset Password 1.2.0+ Fix from $2,3002020-09-18 HIGH 8.8 CVE-2020-25728 The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's… Reset Password 1.2.0+ Fix from $1,9502020-09-17 MEDIUM 5.4 CVE-2020-8776 Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file. Alfresco 5.2.7 / 6.2.0+ Fix from $1,6002020-03-02 MEDIUM 5.4 CVE-2020-8777 Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT e… Alfresco 5.2.7 / 6.2.0+ Fix from $1,6002020-03-02 MEDIUM 5.4 CVE-2020-8778 Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write a… Alfresco 5.2.7 / 6.2.0+ Fix from $1,6002020-03-02 MEDIUM 5.4 CVE-2019-19496 Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document. Alfresco 5.2.5+ Fix from $1,6002019-12-02 MEDIUM 6.1 CVE-2019-14223 An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open … Alfresco 5.2.6+ Fix from $1,6002019-09-06 CRITICAL 9.8 CVE-2019-14222 An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's So… Alfresco after 6.0 Fix from $2,3002019-09-05 HIGH 7.2 CVE-2019-14224EPSS 5% An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit… Alfresco No fix yet Fix from $1,9502019-09-05 CRITICAL 9.8 CVE-2019-15566 The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java. Alfresco 1.8.7+ Fix from $2,3002019-08-26 MEDIUM 5.8 CVE-2015-3366 Cross-site request forgery (CSRF) vulnerability in the Alfresco module before 6.x-1.3 for Drupal allows remote attackers to hijack the authentication… Alfresco after 6.x-1.2 Fix from $1,6002015-04-21 MEDIUM 5.0 CVE-2014-9302 Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Communi… Community Edition after 5.0.a Fix from $1,6002014-12-07 MEDIUM 6.4 CVE-2014-9301 Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger o… Alfresco after 4.2.f Fix from $1,6002014-12-07 MEDIUM 6.8 CVE-2014-9300 Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Communit… Alfresco after 5.0.a Fix from $1,6002014-12-07