Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-35984 A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitr… Rukovoditel No fix yet Fix from $1,6002021-07-09 MEDIUM 5.4 CVE-2020-35985 A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitr… Rukovoditel No fix yet Fix from $1,6002021-07-09 MEDIUM 5.4 CVE-2020-35986 A stored cross site scripting (XSS) vulnerability in the 'Users Access Groups' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute… Rukovoditel No fix yet Fix from $1,6002021-07-09 MEDIUM 5.4 CVE-2020-35987 A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbit… Rukovoditel No fix yet Fix from $1,6002021-07-09 HIGH 8.8 CVE-2021-30224 Cross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials. Rukovoditel Patch available Fix from $1,9502021-04-29 HIGH 8.8 CVE-2020-13591 An exploitable SQL injection vulnerability exists in the "access_rules/rules_form" page of the Rukovoditel Project Management App 2.7.2. A specially … Rukovoditel No fix yet Fix from $1,9502021-04-09 HIGH 8.8 CVE-2020-13592 An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. A specially crafted… Rukovoditel No fix yet Fix from $1,9502021-04-09 HIGH 8.8 CVE-2020-13587 An exploitable SQL injection vulnerability exists in the "forms_fields_rules/rules" page of the Rukovoditel Project Management App 2.7.2. A specially… Rukovoditel No fix yet Fix from $1,9502021-04-09 MEDIUM 6.1 CVE-2020-21732 Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code to the filename. Rukovoditel Mitigation only Fix from $1,6002020-09-14 CRITICAL 9.8 CVE-2020-11817 In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacke… Rukovoditel No fix yet Fix from $2,3002020-04-27 MEDIUM 6.1 CVE-2020-11822 In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus, an attacker can inject mali… Rukovoditel No fix yet Fix from $1,6002020-04-27 MEDIUM 5.3 CVE-2020-11821 In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can ea… Rukovoditel No fix yet Fix from $1,6002020-04-27 CRITICAL 9.8 CVE-2020-11812 Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the filters[0][value] or filters[1][value] parameter. Rukovoditel Mitigation only Fix from $2,3002020-04-16 CRITICAL 9.8 CVE-2020-11815 In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can… Rukovoditel No fix yet Fix from $2,3002020-04-16 CRITICAL 9.8 CVE-2020-11816 Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the reports_id (POST) parameter. Rukovoditel No fix yet Fix from $2,3002020-04-16 CRITICAL 9.8 CVE-2020-11819EPSS 27% In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve command execution. Rukovoditel No fix yet Fix from $2,3002020-04-16 CRITICAL 9.8 CVE-2020-11820 Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the entities_id parameter. Rukovoditel No fix yet Fix from $2,3002020-04-16 HIGH 8.8 CVE-2020-11818 In Rukovoditel 2.5.2 has a form_session_token value to prevent CSRF attacks. This protection mechanism can be bypassed with another user's valid toke… Rukovoditel No fix yet Fix from $1,9502020-04-16 MEDIUM 5.4 CVE-2020-11813 In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the configuration page via the copyright text input. Thus, an attacker can inject a mali… Rukovoditel Mitigation only Fix from $1,6002020-04-16 MEDIUM 6.1 CVE-2019-7541 Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring. Rukovoditel after 2.4.1 Fix from $1,6002019-05-07 MEDIUM 6.1 CVE-2019-7400EPSS 6% Rukovoditel before 2.4.1 allows XSS. Rukovoditel 2.4.1+ Fix from $1,6002019-02-05 HIGH 8.8 CVE-2018-20166EPSS 7% A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishan… Rukovoditel No fix yet Fix from $1,9502019-01-02