Vulnerability index

Browse CVEs

145 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dedecms HIGH 7.2
CVE-2022-40921

DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.

No fix yet
Fix from $1,950 2022-10-12
Dedecms HIGH 7.2
CVE-2022-40886

DedeCMS 5.7.98 has a file upload vulnerability in the background.

No fix yet
Fix from $1,950 2022-10-03
Dedecms MEDIUM 6.1
CVE-2022-36583

DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parame…

No fix yet
Fix from $1,600 2022-09-01
Dedecms CRITICAL 9.8
CVE-2022-35516

DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.

Fix: after 5.7.96
Fix from $2,300 2022-08-17
Dedecms HIGH 7.2
CVE-2022-36216

DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.

Fix: after 5.7.97
Fix from $1,950 2022-08-17
Dedecms CRITICAL 9.8
CVE-2022-34531EPSS 23%

DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.

No fix yet
Fix from $2,300 2022-07-29
Dedecms MEDIUM 6.5
CVE-2022-30508

DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.

No fix yet
Fix from $1,600 2022-05-26
Dedecms CRITICAL 9.8
CVE-2022-23337

DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.

No fix yet
Fix from $2,300 2022-02-14
Dedecms MEDIUM 6.1
CVE-2020-36494

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component mychannel_edit.php via the `filename`…

No fix yet
Fix from $1,600 2021-10-22
Dedecms MEDIUM 6.1
CVE-2020-36495

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `filenam…

No fix yet
Fix from $1,600 2021-10-22
Dedecms MEDIUM 6.1
CVE-2020-36496

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component sys_admin_user_edit.php via the `file…

No fix yet
Fix from $1,600 2021-10-22
Dedecms MEDIUM 6.1
CVE-2020-36497

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filena…

No fix yet
Fix from $1,600 2021-10-22
Dedecms MEDIUM 5.4
CVE-2020-36490

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activep…

No fix yet
Fix from $1,600 2021-10-22
Dedecms MEDIUM 5.4
CVE-2020-36491

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `…

No fix yet
Fix from $1,600 2021-10-22
Dedecms MEDIUM 5.4
CVE-2020-36492

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component select_media.php via the `activepath`…

No fix yet
Fix from $1,600 2021-10-22
Dedecms MEDIUM 5.4
CVE-2020-36493

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, …

No fix yet
Fix from $1,600 2021-10-22
Dedecms MEDIUM 6.1
CVE-2020-23046

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the `filename`, `mid`, `u…

No fix yet
Fix from $1,600 2021-10-22
Dedecms MEDIUM 5.4
CVE-2020-23044

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath…

No fix yet
Fix from $1,600 2021-10-22
Dedecms CRITICAL 9.8
CVE-2020-18114

An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.

No fix yet
Fix from $2,300 2021-08-27
Dedecms HIGH 8.8
CVE-2020-18917

The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the content…

No fix yet
Fix from $1,950 2021-08-24
Dedecms CRITICAL 9.8
CVE-2020-22198

SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.

No fix yet
Fix from $2,300 2021-06-16
Dedecms HIGH 8.8
CVE-2021-32073

DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code e…

No fix yet
Fix from $1,950 2021-05-15
Dedecms MEDIUM 5.4
CVE-2020-16632

A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyw…

No fix yet
Fix from $1,600 2021-05-15
Dedecms MEDIUM 5.4
CVE-2020-27533

A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, a…

No fix yet
Fix from $1,600 2020-10-22
Dedecms HIGH 8.8
CVE-2015-4553EPSS 57%

A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.

Fix: after 5.6
Fix from $1,950 2020-01-06
Dedecms MEDIUM 6.5
CVE-2019-10014

In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, …

No fix yet
Fix from $1,600 2019-03-24
Dedecms HIGH 8.8
CVE-2019-8933

In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execu…

No fix yet
Fix from $1,950 2019-02-19
Dedecms HIGH 7.5
CVE-2019-8362

DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=sa…

Fix: 5.7+
Fix from $1,950 2019-02-16
Dedecms HIGH 8.8
CVE-2019-6289

uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file ex…

Mitigation only
Fix from $1,950 2019-01-15
Dedecms HIGH 8.8
CVE-2018-20129EPSS 8%

An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PH…

No fix yet
Fix from $1,950 2018-12-13