Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-26846 A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload … Opencats Mitigation only Fix from $1,6002023-04-11 MEDIUM 5.4 CVE-2023-26847 A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload … Opencats Mitigation only Fix from $1,6002023-04-11 MEDIUM 6.1 CVE-2023-27293EPSS 57% Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a ques… Opencats No fix yet Fix from $1,6002023-02-28 MEDIUM 5.4 CVE-2023-27292 An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters. Opencats No fix yet Fix from $1,6002023-02-28 MEDIUM 5.4 CVE-2023-27294 Improper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit malicious … Opencats No fix yet Fix from $1,6002023-02-28 MEDIUM 5.4 CVE-2023-27295 Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue by creating… Opencats No fix yet Fix from $1,6002023-02-28 CRITICAL 9.8 CVE-2022-48011 Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function. Opencats No fix yet Fix from $2,3002023-01-27 MEDIUM 6.1 CVE-2022-48012 Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=aja… Opencats No fix yet Fix from $1,6002023-01-27 MEDIUM 5.4 CVE-2022-48013 Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar. This vul… Opencats No fix yet Fix from $1,6002023-01-27 MEDIUM 6.5 CVE-2022-43023 OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function. Opencats No fix yet Fix from $1,6002022-10-19 CRITICAL 9.8 CVE-2022-43019 OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality. Opencats No fix yet Fix from $2,3002022-10-19 MEDIUM 6.5 CVE-2022-43020 OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function. Opencats No fix yet Fix from $1,6002022-10-19 MEDIUM 6.5 CVE-2022-43021 OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable. Opencats No fix yet Fix from $1,6002022-10-19 MEDIUM 6.5 CVE-2022-43022 OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function. Opencats No fix yet Fix from $1,6002022-10-19 MEDIUM 6.1 CVE-2022-43014 OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter. Opencats No fix yet Fix from $1,6002022-10-19 MEDIUM 6.1 CVE-2022-43015 OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter. Opencats No fix yet Fix from $1,6002022-10-19 MEDIUM 6.1 CVE-2022-43016 OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component. Opencats No fix yet Fix from $1,6002022-10-19 MEDIUM 6.1 CVE-2022-43017 OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component. Opencats No fix yet Fix from $1,6002022-10-19 MEDIUM 6.1 CVE-2022-43018 OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function. Opencats No fix yet Fix from $1,6002022-10-19 CRITICAL 9.8 CVE-2021-41560EPSS 11% OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php. Opencats after 0.9.6 Fix from $2,3002021-12-15 MEDIUM 6.1 CVE-2021-25295 OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues. Opencats after 0.9.5-3 Fix from $1,6002021-01-18 CRITICAL 9.8 CVE-2021-25294EPSS 11% OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occurs because lib/DataGrid.php … Opencats after 0.9.5-3 Fix from $2,3002021-01-18 HIGH 7.5 CVE-2019-13358EPSS 24% lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker mus… Opencats 0.9.4-3+ Fix from $1,9502019-07-05