Vulnerability index

Browse CVEs

145 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2022-40921 DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php. Dedecms No fix yet Fix from $1,9502022-10-12 HIGH 7.2 CVE-2022-40886 DedeCMS 5.7.98 has a file upload vulnerability in the background. Dedecms No fix yet Fix from $1,9502022-10-03 MEDIUM 6.1 CVE-2022-36583 DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parame… Dedecms No fix yet Fix from $1,6002022-09-01 CRITICAL 9.8 CVE-2022-35516 DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php. Dedecms after 5.7.96 Fix from $2,3002022-08-17 HIGH 7.2 CVE-2022-36216 DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php. Dedecms after 5.7.97 Fix from $1,9502022-08-17 CRITICAL 9.8 CVE-2022-34531EPSS 23% DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php. Dedecms No fix yet Fix from $2,3002022-07-29 MEDIUM 6.5 CVE-2022-30508 DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter. Dedecms No fix yet Fix from $1,6002022-05-26 CRITICAL 9.8 CVE-2022-23337 DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter. Dedecms No fix yet Fix from $2,3002022-02-14 MEDIUM 6.1 CVE-2020-36494 DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component mychannel_edit.php via the `filename`… Dedecms No fix yet Fix from $1,6002021-10-22 MEDIUM 6.1 CVE-2020-36495 DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `filenam… Dedecms No fix yet Fix from $1,6002021-10-22 MEDIUM 6.1 CVE-2020-36496 DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component sys_admin_user_edit.php via the `file… Dedecms No fix yet Fix from $1,6002021-10-22 MEDIUM 6.1 CVE-2020-36497 DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filena… Dedecms No fix yet Fix from $1,6002021-10-22 MEDIUM 5.4 CVE-2020-36490 DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activep… Dedecms No fix yet Fix from $1,6002021-10-22 MEDIUM 5.4 CVE-2020-36491 DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `… Dedecms No fix yet Fix from $1,6002021-10-22 MEDIUM 5.4 CVE-2020-36492 DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component select_media.php via the `activepath`… Dedecms No fix yet Fix from $1,6002021-10-22 MEDIUM 5.4 CVE-2020-36493 DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, … Dedecms No fix yet Fix from $1,6002021-10-22 MEDIUM 6.1 CVE-2020-23046 DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the `filename`, `mid`, `u… Dedecms No fix yet Fix from $1,6002021-10-22 MEDIUM 5.4 CVE-2020-23044 DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath… Dedecms No fix yet Fix from $1,6002021-10-22 CRITICAL 9.8 CVE-2020-18114 An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format. Dedecms No fix yet Fix from $2,3002021-08-27 HIGH 8.8 CVE-2020-18917 The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the content… Dedecms No fix yet Fix from $1,9502021-08-24 CRITICAL 9.8 CVE-2020-22198 SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php. Dedecms No fix yet Fix from $2,3002021-06-16 HIGH 8.8 CVE-2021-32073 DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code e… Dedecms No fix yet Fix from $1,9502021-05-15 MEDIUM 5.4 CVE-2020-16632 A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyw… Dedecms No fix yet Fix from $1,6002021-05-15 MEDIUM 5.4 CVE-2020-27533 A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, a… Dedecms No fix yet Fix from $1,6002020-10-22 HIGH 8.8 CVE-2015-4553EPSS 57% A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell. Dedecms after 5.6 Fix from $1,9502020-01-06 MEDIUM 6.5 CVE-2019-10014 In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, … Dedecms No fix yet Fix from $1,6002019-03-24 HIGH 8.8 CVE-2019-8933 In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execu… Dedecms No fix yet Fix from $1,9502019-02-19 HIGH 7.5 CVE-2019-8362 DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=sa… Dedecms 5.7+ Fix from $1,9502019-02-16 HIGH 8.8 CVE-2019-6289 uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file ex… Dedecms Mitigation only Fix from $1,9502019-01-15 HIGH 8.8 CVE-2018-20129EPSS 8% An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PH… Dedecms No fix yet Fix from $1,9502018-12-13