Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-53909 MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypasse… Mycomplianceoffice Mitigation only Fix from $1,6002026-07-01 HIGH 8.2 CVE-2026-53906 MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the … Mycomplianceoffice Mitigation only Fix from $1,9502026-07-01 HIGH 8.1 CVE-2026-53903 MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement … Mycomplianceoffice Mitigation only Fix from $1,9502026-07-01 HIGH 7.1 CVE-2026-53904 MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidate… Mco Mitigation only Fix from $1,9502026-07-01 HIGH 7.1 CVE-2026-53905 MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authe… Mycomplianceoffice Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.5 CVE-2026-53902 MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated u… Mycomplianceoffice Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.4 CVE-2026-53907 MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the appl… Mycomplianceoffice Mitigation only Fix from $1,6002026-07-01