Vulnerability index

Browse CVEs

47 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-53913 Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attac… Rukovoditel No fix yet Fix from $1,9502025-12-17 MEDIUM 5.4 CVE-2023-53898 Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers ca… Rukovoditel No fix yet Fix from $1,6002025-12-16 MEDIUM 5.4 CVE-2023-53897 Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attac… Rukovoditel No fix yet Fix from $1,6002025-12-16 CRITICAL 9.8 CVE-2022-48175 Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/aja… Rukovoditel No fix yet Fix from $2,3002023-01-30 HIGH 8.8 CVE-2022-45020 Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=user… Rukovoditel No fix yet Fix from $1,9502022-12-05 CRITICAL 9.8 CVE-2022-44945 Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter. Rukovoditel Mitigation only Fix from $2,3002022-12-02 MEDIUM 5.4 CVE-2022-44944 Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=… Rukovoditel No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44946 Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pag… Rukovoditel No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44947 Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=enti… Rukovoditel No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44948 Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=enti… Rukovoditel No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44949 Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=ent… Rukovoditel No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44950 Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=ent… Rukovoditel No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44951 Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=… Rukovoditel No fix yet Fix from $1,6002022-12-02 MEDIUM 5.4 CVE-2022-44952 Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This v… Rukovoditel No fix yet Fix from $1,6002022-12-02 HIGH 8.8 CVE-2022-43288 Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/index.php?module=logs/view&type… Rukovoditel No fix yet Fix from $1,9502022-11-14 CRITICAL 9.8 CVE-2022-43168 Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter. Rukovoditel No fix yet Fix from $2,3002022-10-28 MEDIUM 5.4 CVE-2022-43165 A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1 allows a… Rukovoditel No fix yet Fix from $1,6002022-10-28 MEDIUM 5.4 CVE-2022-43166 A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1 allows a… Rukovoditel No fix yet Fix from $1,6002022-10-28 MEDIUM 5.4 CVE-2022-43167 A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 all… Rukovoditel No fix yet Fix from $1,6002022-10-28 MEDIUM 5.4 CVE-2022-43169 A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.… Rukovoditel No fix yet Fix from $1,6002022-10-28 MEDIUM 5.4 CVE-2022-43170 A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel … Rukovoditel No fix yet Fix from $1,6002022-10-28 MEDIUM 5.4 CVE-2022-43164 A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows aut… Rukovoditel No fix yet Fix from $1,6002022-10-28 MEDIUM 5.4 CVE-2022-43185 A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary we… Rukovoditel No fix yet Fix from $1,6002022-10-19 HIGH 7.2 CVE-2020-13590 Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially c… Rukovoditel No fix yet Fix from $1,9502022-04-18 MEDIUM 5.4 CVE-2020-18469 Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel… Rukovoditel No fix yet Fix from $1,6002021-08-26 MEDIUM 5.4 CVE-2020-18470 Stored cross-site scripting (XSS) vulnerability in the Name of application field found in the General Configuration page in Rukovoditel 2.4.1 allows … Rukovoditel No fix yet Fix from $1,6002021-08-26 HIGH 8.8 CVE-2020-13588 An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id… Rukovoditel No fix yet Fix from $1,9502021-08-17 HIGH 8.8 CVE-2020-13589 An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The entities_id para… Rukovoditel No fix yet Fix from $1,9502021-08-17 MEDIUM 5.4 CVE-2020-35984 A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitr… Rukovoditel No fix yet Fix from $1,6002021-07-09 MEDIUM 5.4 CVE-2020-35985 A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitr… Rukovoditel No fix yet Fix from $1,6002021-07-09