Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Plesk HIGH 7.8
CVE-2023-4931

Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injectin…

Mitigation only
Fix from $1,950 2023-11-27
Onyx HIGH 7.5
CVE-2023-43784

Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is th…

No fix yet
Fix from $1,950 2023-09-22
Obsidian MEDIUM 6.5
CVE-2022-45130

Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of…

No fix yet
Fix from $1,600 2022-11-10
Plesk HIGH 8.8
CVE-2021-45008

Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor st…

No fix yet
Fix from $1,950 2022-02-21
Plesk MEDIUM 6.5
CVE-2021-45007

Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NO…

No fix yet
Fix from $1,600 2022-02-20
Obsidian MEDIUM 6.1
CVE-2020-11583

A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS vi…

Mitigation only
Fix from $1,600 2020-08-03
Onyx MEDIUM 6.1
CVE-2020-11584

A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a …

Mitigation only
Fix from $1,600 2020-08-03