Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dzzoffice HIGH 8.8
CVE-2024-41376

dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.

No fix yet
Fix from $1,950 2024-08-05
Dzzoffice MEDIUM 6.1
CVE-2024-29273

There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.

No fix yet
Fix from $1,600 2024-03-22
Dzzoffice MEDIUM 6.5
CVE-2023-39853

SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent parameters i…

No fix yet
Fix from $1,600 2024-01-06
Dzzoffice MEDIUM 6.1
CVE-2021-30203

A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scri…

No fix yet
Fix from $1,600 2023-06-27
Dzzoffice MEDIUM 5.3
CVE-2021-30205

Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse dep…

No fix yet
Fix from $1,600 2023-06-27
Dzzoffice HIGH 8.8
CVE-2022-43340

A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights t…

Mitigation only
Fix from $1,950 2022-10-27
Dzzoffice MEDIUM 6.1
CVE-2021-43673

dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of the exit function is printed fo…

No fix yet
Fix from $1,600 2021-12-03
Dzzoffice MEDIUM 5.4
CVE-2021-40292

A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.

No fix yet
Fix from $1,600 2021-10-12
Dzzoffice MEDIUM 5.4
CVE-2021-40191

Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all upload functions in webroot/dzz…

No fix yet
Fix from $1,600 2021-10-11
Dzzoffice MEDIUM 6.1
CVE-2020-19703

A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a…

No fix yet
Fix from $1,600 2021-08-26