Vulnerability index

Browse CVEs

44 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-3106 Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' paramet… Teampass 3.1.5.24+ Fix from $1,6002026-03-31 MEDIUM 5.4 CVE-2026-3107 Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpo… Teampass 3.1.5.24+ Fix from $1,6002026-03-31 HIGH 8.1 CVE-2024-50703 TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. Teampass 3.1.3.1+ Fix from $1,9502024-12-30 MEDIUM 5.3 CVE-2024-50702 TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. Teampass 3.1.3.1+ Fix from $1,6002024-12-30 MEDIUM 5.4 CVE-2023-3565 Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Teampass 3.0.10+ Fix from $1,6002023-07-10 HIGH 7.5 CVE-2023-3553 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Teampass 3.0.10+ Fix from $1,9502023-07-08 MEDIUM 5.4 CVE-2023-3552 Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Teampass 3.0.10+ Fix from $1,6002023-07-08 HIGH 7.2 CVE-2023-3551 Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Teampass 3.0.10+ Fix from $1,9502023-07-08 MEDIUM 5.4 CVE-2023-3531 Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. Teampass 3.0.10+ Fix from $1,6002023-07-06 MEDIUM 5.4 CVE-2023-3191 Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Teampass 3.0.9+ Fix from $1,6002023-06-10 MEDIUM 6.5 CVE-2023-3095 Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Teampass 3.0.9+ Fix from $1,6002023-06-04 CRITICAL 9.0 CVE-2023-3086 Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Teampass 3.0.9+ Fix from $2,3002023-06-03 HIGH 8.1 CVE-2023-3084 Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Teampass 3.0.9+ Fix from $1,9502023-06-03 HIGH 8.7 CVE-2023-3083 Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Teampass 3.0.9+ Fix from $1,9502023-06-03 MEDIUM 5.4 CVE-2023-3009 Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Teampass 3.0.9+ Fix from $1,6002023-05-31 HIGH 8.8 CVE-2023-2859 Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9. Teampass 3.0.9+ Fix from $1,9502023-05-24 MEDIUM 5.4 CVE-2023-2591 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7. Teampass 3.0.7+ Fix from $1,6002023-05-09 MEDIUM 5.4 CVE-2023-2516 Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7. Teampass 3.0.7+ Fix from $1,6002023-05-05 MEDIUM 5.4 CVE-2023-2021 Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3. Teampass 3.0.3+ Fix from $1,6002023-04-13 HIGH 7.5 CVE-2023-1545EPSS 8% SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. Teampass 3.0.0.23+ Fix from $1,9502023-03-21 MEDIUM 5.4 CVE-2023-1463 Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. Teampass 3.0.0.23+ Fix from $1,6002023-03-17 HIGH 7.1 CVE-2023-1070 External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. Teampass 3.0.0.22+ Fix from $1,9502023-02-27 MEDIUM 6.1 CVE-2022-26980 Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO. Teampass Patch available Fix from $1,6002022-03-28 HIGH 8.1 CVE-2020-11671 Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPa… Teampass after 2.1.27.36 Fix from $1,9502020-05-04 HIGH 8.8 CVE-2020-12479 TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.q… Teampass No fix yet Fix from $1,9502020-04-29 HIGH 7.5 CVE-2020-12477 The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For… Teampass No fix yet Fix from $1,9502020-04-29 HIGH 7.5 CVE-2020-12478EPSS 8% TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files. Teampass No fix yet Fix from $1,9502020-04-29 MEDIUM 6.1 CVE-2019-17205 TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of fai… Teampass No fix yet Fix from $1,6002019-10-05 MEDIUM 5.4 CVE-2019-17204 TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item. Teampass No fix yet Fix from $1,6002019-10-05 MEDIUM 5.4 CVE-2019-17203 TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder. Teampass No fix yet Fix from $1,6002019-10-05