Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.2
CVE-2019-25669
qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_ext…
Qdpm
after 9.1
HIGH 8.2
CVE-2018-25208
qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through …
Qdpm
after 9.1
CRITICAL 9.8
CVE-2023-45856
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
Qdpm
No fix yet
HIGH 7.5
CVE-2023-45855
qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
Qdpm
No fix yet
HIGH 8.8
CVE-2022-26180
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
Qdpm
No fix yet
MEDIUM 6.1
CVE-2020-19515
qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.
Qdpm
No fix yet
MEDIUM 5.4
CVE-2020-18468
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted we…
Qdpm
No fix yet
HIGH 8.8
CVE-2020-26165
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php beca…
Qdpm
after 9.1
MEDIUM 5.4
CVE-2020-26166
The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTM…
Qdpm
Mitigation only
CRITICAL 9.8
CVE-2020-11811
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type va…
Qdpm
No fix yet
MEDIUM 5.4
CVE-2020-11814
A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious websites.
Qdpm
No fix yet
HIGH 8.8
CVE-2020-7246EPSS 83%
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo fu…
Qdpm
after 9.1
MEDIUM 6.1
CVE-2019-8391
qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
Qdpm
No fix yet
MEDIUM 6.1
CVE-2019-8390EPSS 10%
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
Qdpm
No fix yet
HIGH 8.8
CVE-2015-3884EPSS 14%
Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pa…
Qdpm
after 9.1
HIGH 7.5
CVE-2015-3881
Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.ym…
Qdpm
No fix yet
MEDIUM 6.1
CVE-2015-3883
Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) search[keyw…
Qdpm
No fix yet
MEDIUM 5.3
CVE-2015-3882
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation…
Qdpm
No fix yet