Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2020-5188 DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions. Dotnetnuke after 9.4.4 Fix from $1,6002020-02-24 MEDIUM 5.4 CVE-2020-5186 DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2). Dotnetnuke after 9.4.4 Fix from $1,6002020-02-24 MEDIUM 6.1 CVE-2019-12562EPSS 6% Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin n… Dotnetnuke 9.4.0+ Fix from $1,6002019-09-26 HIGH 7.5 CVE-2018-15811 KEVEPSS 74% DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. Dotnetnuke after 9.2.1 Fix from $1,9502019-07-03 HIGH 7.5 CVE-2018-15812EPSS 47% DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy. Dotnetnuke after 9.2.1 Fix from $1,9502019-07-03 HIGH 7.5 CVE-2018-18325 KEVEPSS 74% DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete… Dotnetnuke after 9.2.2 Fix from $1,9502019-07-03 HIGH 7.5 CVE-2018-18326EPSS 54% DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue … Dotnetnuke after 9.2.2 Fix from $1,9502019-07-03 MEDIUM 6.1 CVE-2018-14486 DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML. Dotnetnuke No fix yet Fix from $1,6002019-03-21 HIGH 7.5 CVE-2017-0929EPSS 13% DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able… Dotnetnuke 9.2.0+ Fix from $1,9502018-07-03 HIGH 8.8 CVE-2017-9822 KEVEPSS 95% DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." Dotnetnuke 9.1.1+ Fix from $1,9502017-07-20 CRITICAL 9.8 CVE-2015-2794EPSS 75% The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct … Dotnetnuke after 07.04.00 Fix from $2,3002017-02-06 MEDIUM 5.4 CVE-2016-7119 Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to … Dotnetnuke after 08.00.04 Fix from $1,6002016-08-31 MEDIUM 5.0 CVE-2009-4109 The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need… Dotnetnuke Mitigation only Fix from $1,6002009-11-29 HIGH 7.5 CVE-2008-7102 DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unk… Dotnetnuke Patch available Fix from $1,9502009-08-27 MEDIUM 6.5 CVE-2008-7100 Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknow… Dotnetnuke Patch available Fix from $1,6002009-08-27 MEDIUM 5.0 CVE-2008-7101 Unspecified vulnerability in DotNetNuke 4.0 through 4.8.4 and 5.0 allows remote attackers to obtain sensitive information (portal number) by accessin… Dotnetnuke Patch available Fix from $1,6002009-08-27 MEDIUM 6.8 CVE-2008-6541 Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files a… Dotnetnuke after 4.8.1 Fix from $1,6002009-03-30 MEDIUM 5.1 CVE-2008-6540 DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey val… Dotnetnuke after 4.8.1 Fix from $1,6002009-03-30 MEDIUM 6.4 CVE-2008-6399 Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack … Dotnetnuke Mitigation only Fix from $1,6002009-03-05 HIGH 10.0 CVE-2006-3601 ** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privile… Dotnetnuke No fix yet Fix from $1,9502006-07-18 HIGH 7.5 CVE-2004-2324 SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database vi… Dotnetnuke Patch available Fix from $1,9502004-12-31 MEDIUM 5.0 CVE-2004-2323 DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server userna… Dotnetnuke Patch available Fix from $1,6002004-12-31