Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2019-25669 qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_ext… Qdpm after 9.1 Fix from $1,9502026-04-05 HIGH 8.2 CVE-2018-25208 qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through … Qdpm after 9.1 Fix from $1,9502026-03-26 CRITICAL 9.8 CVE-2023-45856 qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI. Qdpm No fix yet Fix from $2,3002023-10-14 HIGH 7.5 CVE-2023-45855 qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI. Qdpm No fix yet Fix from $1,9502023-10-14 HIGH 8.8 CVE-2022-26180 qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI. Qdpm No fix yet Fix from $1,9502022-04-08 MEDIUM 6.1 CVE-2020-19515 qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php. Qdpm No fix yet Fix from $1,6002021-09-09 MEDIUM 5.4 CVE-2020-18468 Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted we… Qdpm No fix yet Fix from $1,6002021-08-26 HIGH 8.8 CVE-2020-26165 qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php beca… Qdpm after 9.1 Fix from $1,9502020-12-31 MEDIUM 5.4 CVE-2020-26166 The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTM… Qdpm Mitigation only Fix from $1,6002020-10-05 CRITICAL 9.8 CVE-2020-11811 In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type va… Qdpm No fix yet Fix from $2,3002020-04-16 MEDIUM 5.4 CVE-2020-11814 A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious websites. Qdpm No fix yet Fix from $1,6002020-04-16 HIGH 8.8 CVE-2020-7246EPSS 83% A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo fu… Qdpm after 9.1 Fix from $1,9502020-01-21 MEDIUM 6.1 CVE-2019-8391 qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter. Qdpm No fix yet Fix from $1,6002019-05-14 MEDIUM 6.1 CVE-2019-8390EPSS 10% qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter. Qdpm No fix yet Fix from $1,6002019-05-14 HIGH 8.8 CVE-2015-3884EPSS 14% Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pa… Qdpm after 9.1 Fix from $1,9502017-03-17 HIGH 7.5 CVE-2015-3881 Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.ym… Qdpm No fix yet Fix from $1,9502017-03-17 MEDIUM 6.1 CVE-2015-3883 Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) search[keyw… Qdpm No fix yet Fix from $1,6002017-03-17 MEDIUM 5.3 CVE-2015-3882 qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation… Qdpm No fix yet Fix from $1,6002017-03-17