Vulnerability index

Browse CVEs

44 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Teampass MEDIUM 5.4
CVE-2019-16904

TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The c…

No fix yet
Fix from $1,600 2019-09-26
Teampass MEDIUM 5.4
CVE-2019-12950

An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file w…

No fix yet
Fix from $1,600 2019-08-06
Teampass CRITICAL 9.8
CVE-2019-1000001

TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in a…

Fix: after 2.1.27.0
Fix from $2,300 2019-02-04
Teampass HIGH 8.1
CVE-2017-15055

TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary i…

Fix: 2.1.27.9+
Fix from $1,950 2017-11-27
Teampass HIGH 7.5
CVE-2017-15054

An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to R…

Fix: 2.1.27.9+
Fix from $1,950 2017-11-27
Teampass MEDIUM 5.4
CVE-2017-15051

Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject arbitrary web s…

Fix: 2.1.27.9+
Fix from $1,600 2017-11-27
Teampass MEDIUM 5.4
CVE-2017-15278

Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/f…

Fix: after 2.1.27.8
Fix from $1,600 2017-10-12
Teampass CRITICAL 9.8
CVE-2017-9436

TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.

Patch available
Fix from $2,300 2017-06-05
Teampass CRITICAL 9.8
CVE-2015-7564

Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id paramet…

Fix: after 2.1.24
Fix from $2,300 2017-04-12
Teampass HIGH 8.8
CVE-2015-7563

Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticat…

Fix: after 2.1.24.0
Fix from $1,950 2017-04-12
Teampass MEDIUM 6.1
CVE-2015-7562

Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via …

Fix: after 2.1.24
Fix from $1,600 2017-04-12
Teampass HIGH 7.5
CVE-2014-3771

TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via the language file path in a (1) request to index.php or (2) "change_…

Fix: after 2.1.20
Fix from $1,950 2014-08-07
Teampass HIGH 7.5
CVE-2014-3772

TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a direct request to a file that c…

Fix: after 2.1.20
Fix from $1,950 2014-08-07
Teampass HIGH 7.5
CVE-2014-3773

Multiple SQL injection vulnerabilities in TeamPass before 2.1.20 allow remote attackers to execute arbitrary SQL commands via the login parameter in …

Fix: after 2.1.20
Fix from $1,950 2014-08-07