Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pydio MEDIUM 5.4
CVE-2024-40124

Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.

Fix: after 8.2.5
Fix from $1,600 2025-04-17
Cells MEDIUM 6.5
CVE-2023-32750

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. Th…

Fix: 3.0.12 / 4.1.3+
Fix from $1,600 2023-06-08
Cells MEDIUM 5.4
CVE-2023-32751

Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the Amazon AWS SDK …

Fix: 3.0.12 / 4.1.3+
Fix from $1,600 2023-06-08
Cells HIGH 8.8
CVE-2023-32749EPSS 14%

Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when cre…

Fix: 3.0.12 / 4.1.3+
Fix from $1,950 2023-06-08
Cells MEDIUM 6.5
CVE-2021-41324

Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cel…

Mitigation only
Fix from $1,600 2021-09-30
Cells MEDIUM 6.5
CVE-2021-41323

Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells files belong…

Mitigation only
Fix from $1,600 2021-09-30
Cells MEDIUM 6.5
CVE-2021-41325

Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile parameter. (In ad…

Mitigation only
Fix from $1,600 2021-09-30
Cells HIGH 7.0
CVE-2020-12850

The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as v…

No fix yet
Fix from $1,950 2020-06-11
Cells MEDIUM 5.4
CVE-2020-12848

In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shared user account is created in …

No fix yet
Fix from $1,600 2020-06-05
Cells MEDIUM 5.4
CVE-2020-12849

Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user roles. These profile pictures …

No fix yet
Fix from $1,600 2020-06-05
Cells HIGH 8.1
CVE-2020-12851

Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by up…

No fix yet
Fix from $1,950 2020-06-04
Cells HIGH 7.2
CVE-2020-12847

Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role. This …

No fix yet
Fix from $1,950 2020-06-04
Cells MEDIUM 6.8
CVE-2020-12852

The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the download…

No fix yet
Fix from $1,600 2020-06-04
Cells MEDIUM 6.1
CVE-2020-12853

Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to…

No fix yet
Fix from $1,600 2020-06-04
Pydio HIGH 8.8
CVE-2019-20452

A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/s…

Fix: 8.2.4+
Fix from $1,950 2020-03-17
Pydio HIGH 8.8
CVE-2019-20453

A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http…

Fix: 8.2.4+
Fix from $1,950 2020-03-17
Pydio CRITICAL 9.8
CVE-2013-4267

Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Powe…

Fix: 5.0.1+
Fix from $2,300 2020-02-11
Pydio HIGH 7.7
CVE-2019-15033

Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to ind…

No fix yet
Fix from $1,950 2019-09-19
Pydio MEDIUM 5.3
CVE-2019-15032

Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhos…

No fix yet
Fix from $1,600 2019-09-19
Cells HIGH 8.8
CVE-2019-12901

Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders…

Fix: 1.5.0+
Fix from $1,950 2019-06-20
Cells MEDIUM 6.5
CVE-2019-12902

Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, …

Fix: 1.5.0+
Fix from $1,600 2019-06-20
Pydio CRITICAL 9.8
CVE-2019-9642

An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP …

Fix: after 8.2.2
Fix from $2,300 2019-06-05
Pydio HIGH 7.3
CVE-2019-10049

It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into opening a l…

Fix: after 8.2.2
Fix from $1,950 2019-05-31
Pydio HIGH 7.2
CVE-2019-10048

The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation and sanitization of user suppl…

Fix: after 8.2.2
Fix from $1,950 2019-05-31
Pydio MEDIUM 5.4
CVE-2019-10047

A stored XSS vulnerability exists in the web application of Pydio through 8.2.2 that can be exploited by levering the file upload and file preview fe…

Fix: after 8.2.2
Fix from $1,600 2019-05-31
Pydio MEDIUM 5.3
CVE-2019-10046

An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information.

No fix yet
Fix from $1,600 2019-05-31
Pydio MEDIUM 6.5
CVE-2019-10045

The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scripts to g…

Fix: after 8.2.2
Fix from $1,600 2019-05-31
Pydio CRITICAL 9.8
CVE-2018-20718

In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a prefer…

Fix: 8.2.2+
Fix from $2,300 2019-01-15
Pydio HIGH 7.2
CVE-2018-14772EPSS 7%

Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web applicat…

Fix: after 8.2.1
Fix from $1,950 2018-10-16
Pydio MEDIUM 6.6
CVE-2018-1999018

Pydio version 8.2.1 and prior contains an Unvalidated user input leading to Remote Code Execution (RCE) vulnerability in plugins/action.antivirus/Ant…

Fix: after 8.2.1
Fix from $1,600 2018-07-23