Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-48235 An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file. Ofcms No fix yet Fix from $1,6002024-10-25 MEDIUM 6.5 CVE-2024-48236 An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-… Ofcms No fix yet Fix from $1,6002024-10-25 CRITICAL 9.8 CVE-2024-34256 OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. Ofcms No fix yet Fix from $2,3002024-05-14 MEDIUM 5.4 CVE-2023-51807 Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title additi… Ofcms No fix yet Fix from $1,6002024-01-16 HIGH 8.8 CVE-2023-24760 An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController. Ofcms No fix yet Fix from $1,9502023-03-16 MEDIUM 6.1 CVE-2022-29653 OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json. Ofcms Mitigation only Fix from $1,6002022-06-02 MEDIUM 5.4 CVE-2022-27960 Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify … Ofcms No fix yet Fix from $1,6002022-04-10 MEDIUM 5.4 CVE-2022-27961 A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a cra… Ofcms No fix yet Fix from $1,6002022-04-10 HIGH 8.8 CVE-2019-9608 An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider… Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 8.8 CVE-2019-9609 An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider… Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 8.8 CVE-2019-9612 An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider… Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 8.8 CVE-2019-9614 An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.ut… Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 8.8 CVE-2019-9617 An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider… Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 7.2 CVE-2019-9613 An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider… Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 7.2 CVE-2019-9615 An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java. Ofcms 1.1.3+ Fix from $1,9502019-03-06 HIGH 7.2 CVE-2019-9616 An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider… Ofcms 1.1.3+ Fix from $1,9502019-03-06 MEDIUM 6.5 CVE-2019-9611 An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir p… Ofcms 1.1.3+ Fix from $1,6002019-03-06