Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Candidats CRITICAL 9.8
CVE-2022-42744

CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application…

No fix yet
Fix from $2,300 2022-11-03
Candidats MEDIUM 6.1
CVE-2022-42746

CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possib…

No fix yet
Fix from $1,600 2022-11-03
Candidats MEDIUM 6.1
CVE-2022-42747

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible …

No fix yet
Fix from $1,600 2022-11-03
Candidats MEDIUM 6.1
CVE-2022-42748

CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is po…

No fix yet
Fix from $1,600 2022-11-03
Candidats MEDIUM 6.1
CVE-2022-42749

CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible be…

No fix yet
Fix from $1,600 2022-11-03
Candidats HIGH 8.8
CVE-2022-42751

CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from C…

No fix yet
Fix from $1,950 2022-11-03
Candidats HIGH 8.8
CVE-2022-42750

CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correct…

No fix yet
Fix from $1,950 2022-11-03
Candidats MEDIUM 6.5
CVE-2022-25228

CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'userID' parameter, in '/in…

No fix yet
Fix from $1,600 2022-08-18
Candidats HIGH 8.8
CVE-2020-9341

CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.

No fix yet
Fix from $1,950 2020-02-22