Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-20915 SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminCont… Publiccms No fix yet Fix from $2,3002023-04-04 MEDIUM 6.1 CVE-2022-3950 A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. Affected is the function initLink of the file dwz.min.js of the… Publiccms 4.0.202204.d+ Fix from $1,6002022-11-11 CRITICAL 9.8 CVE-2021-27693 Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage. Publiccms 4.0.202011.b+ Fix from $2,3002022-09-02 MEDIUM 5.3 CVE-2022-29784 PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java. Publiccms after 4.0.202204.a Fix from $1,6002022-06-03 CRITICAL 9.8 CVE-2022-23389EPSS 22% PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter. Publiccms No fix yet Fix from $2,3002022-02-14 CRITICAL 9.8 CVE-2021-40881 An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code. Publiccms No fix yet Fix from $2,3002021-09-15 MEDIUM 5.4 CVE-2020-21333 Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case. Publiccms No fix yet Fix from $1,6002021-07-09 MEDIUM 5.3 CVE-2018-17368 An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is… Publiccms No fix yet Fix from $1,6002018-09-23 CRITICAL 9.8 CVE-2018-12914 A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a direct… Publiccms No fix yet Fix from $2,3002018-06-27 MEDIUM 6.5 CVE-2018-12493 An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsWebFile/… Publiccms Patch available Fix from $1,6002018-06-15 MEDIUM 6.5 CVE-2018-12494 An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate… Publiccms No fix yet Fix from $1,6002018-06-15 HIGH 8.8 CVE-2018-11500 An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUse… Publiccms No fix yet Fix from $1,9502018-05-26