Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2026-3106
Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' paramet…
Teampass
3.1.5.24+
MEDIUM 5.4
CVE-2026-3107
Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpo…
Teampass
3.1.5.24+
HIGH 8.1
CVE-2024-50703
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.
Teampass
3.1.3.1+
MEDIUM 5.3
CVE-2024-50702
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager.
Teampass
3.1.3.1+
MEDIUM 5.4
CVE-2023-3565
Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
Teampass
3.0.10+
HIGH 7.5
CVE-2023-3553
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
Teampass
3.0.10+
MEDIUM 5.4
CVE-2023-3552
Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
Teampass
3.0.10+
HIGH 7.2
CVE-2023-3551
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
Teampass
3.0.10+
MEDIUM 5.4
CVE-2023-3531
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
Teampass
3.0.10+
MEDIUM 5.4
CVE-2023-3191
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
Teampass
3.0.9+
MEDIUM 6.5
CVE-2023-3095
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
Teampass
3.0.9+
CRITICAL 9.0
CVE-2023-3086
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
Teampass
3.0.9+
HIGH 8.1
CVE-2023-3084
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
Teampass
3.0.9+
HIGH 8.7
CVE-2023-3083
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
Teampass
3.0.9+
MEDIUM 5.4
CVE-2023-3009
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
Teampass
3.0.9+
HIGH 8.8
CVE-2023-2859
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
Teampass
3.0.9+
MEDIUM 5.4
CVE-2023-2591
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.
Teampass
3.0.7+
MEDIUM 5.4
CVE-2023-2516
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.
Teampass
3.0.7+
MEDIUM 5.4
CVE-2023-2021
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.
Teampass
3.0.3+
HIGH 7.5
CVE-2023-1545EPSS 8%
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
Teampass
3.0.0.23+
MEDIUM 5.4
CVE-2023-1463
Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
Teampass
3.0.0.23+
HIGH 7.1
CVE-2023-1070
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.
Teampass
3.0.0.22+
MEDIUM 6.1
CVE-2022-26980
Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.
Teampass
Patch available
HIGH 8.1
CVE-2020-11671
Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPa…
Teampass
after 2.1.27.36
HIGH 8.8
CVE-2020-12479
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.q…
Teampass
No fix yet
HIGH 7.5
CVE-2020-12477
The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For…
Teampass
No fix yet
HIGH 7.5
CVE-2020-12478EPSS 8%
TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.
Teampass
No fix yet
MEDIUM 6.1
CVE-2019-17205
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of fai…
Teampass
No fix yet
MEDIUM 5.4
CVE-2019-17204
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.
Teampass
No fix yet
MEDIUM 5.4
CVE-2019-17203
TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.
Teampass
No fix yet