Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2024-34885 Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts pass… Bitrix24 No fix yet Fix from $1,6002024-11-04 MEDIUM 6.8 CVE-2024-34891 Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account pa… Bitrix24 No fix yet Fix from $1,6002024-11-04 CRITICAL 9.8 CVE-2023-1719 Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments… Bitrix24 No fix yet Fix from $2,3002023-11-01 CRITICAL 9.6 CVE-2023-1716 Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victi… Bitrix24 No fix yet Fix from $2,3002023-11-01 CRITICAL 9.6 CVE-2023-1717 Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execu… Bitrix24 No fix yet Fix from $2,3002023-11-01 HIGH 8.8 CVE-2023-1714 Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to exec… Bitrix24 No fix yet Fix from $1,9502023-11-01 HIGH 8.0 CVE-2023-1720 Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's bro… Bitrix24 No fix yet Fix from $1,9502023-11-01 HIGH 7.5 CVE-2023-1718EPSS 24% Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause den… Bitrix24 No fix yet Fix from $1,9502023-11-01 MEDIUM 5.4 CVE-2023-1715 A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing … Bitrix24 No fix yet Fix from $1,6002023-11-01 HIGH 8.8 CVE-2023-1713 Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote… Bitrix24 No fix yet Fix from $1,9502023-11-01 MEDIUM 5.4 CVE-2017-20122 A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of … Bitrix Site Manager No fix yet Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2020-28206 An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentica… Bitrix Framework No fix yet Fix from $1,6002020-12-02 MEDIUM 6.1 CVE-2008-2052 Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct p… Bitrix Site Manager No fix yet Fix from $1,6002008-05-02