Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-10131 SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter. Searchblox 9.2.1+ Fix from $2,3002023-09-06 HIGH 8.8 CVE-2020-10129 SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to access Admin functionality. Searchblox 9.2.1+ Fix from $1,9502023-09-06 HIGH 8.8 CVE-2020-10130 SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super admin users in the system. Searchblox 9.1+ Fix from $1,9502023-09-06 MEDIUM 6.1 CVE-2020-10132 SearchBlox before Version 9.1 is vulnerable to cross-origin resource sharing misconfiguration. Searchblox 9.1+ Fix from $1,6002023-09-06 MEDIUM 5.4 CVE-2020-10128 SearchBlox product with version before 9.2.1 is vulnerable to stored cross-site scripting at multiple user input parameters. In SearchBlox products m… Searchblox 9.2.1+ Fix from $1,6002023-09-05 HIGH 7.5 CVE-2020-35580EPSS 14% A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files f… Searchblox 9.2.2+ Fix from $1,9502021-05-20 CRITICAL 9.8 CVE-2018-11586EPSS 15% XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct… Searchblox No fix yet Fix from $2,3002018-06-05 HIGH 8.8 CVE-2018-11538EPSS 13% servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token B… Searchblox No fix yet Fix from $1,9502018-06-01 CRITICAL 10.0 CVE-2015-7919EPSS 22% SearchBlox 8.3 before 8.3.1 allows remote attackers to write to the config file, and consequently cause a denial of service (application crash), via … Searchblox Mitigation only Fix from $2,3002015-12-21 HIGH 8.8 CVE-2015-0970 Cross-site request forgery (CSRF) vulnerability in SearchBlox before 8.2 allows remote attackers to hijack the authentication of arbitrary users. Searchblox after 8.1 Fix from $1,9502015-04-18 MEDIUM 5.0 CVE-2015-0969EPSS 13% SearchBlox before 8.2 allows remote attackers to obtain sensitive information via a pretty=true action to the _cluster/health URI. Searchblox after 8.1 Fix from $1,6002015-04-18 HIGH 7.5 CVE-2015-0968 Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox before 8.2 allows remote attackers to execute arbitrary code by upload… Searchblox after 8.1 Fix from $1,9502015-04-18 MEDIUM 6.8 CVE-2013-3590 Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox before 7.5 build 1 allows remote attackers to execute arbitrary code b… Searchblox after 7.5 Fix from $1,6002013-08-28 MEDIUM 5.0 CVE-2013-3597EPSS 8% servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords via a getList action. Searchblox after 7.5 Fix from $1,6002013-08-28 MEDIUM 5.0 CVE-2013-3598 Directory traversal vulnerability in servlet/CreateTemplateServlet in SearchBlox before 7.5 build 1 allows remote attackers to overwrite arbitrary fi… Searchblox after 7.5 Fix from $1,6002013-08-28