Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-5015 A vulnerability was found in UCMS 1.4.7. It has been classified as problematic. Affected is an unknown function of the file ajax.php?do=strarraylist.… Ucms No fix yet Fix from $1,6002023-09-17 MEDIUM 6.1 CVE-2023-2294 A vulnerability was found in UCMS 1.6.0. It has been classified as problematic. This affects an unknown part of the file saddpost.php of the componen… Ucms No fix yet Fix from $1,6002023-04-26 CRITICAL 9.8 CVE-2023-1303 A vulnerability was found in UCMS 1.6 and classified as critical. This issue affects some unknown processing of the file sadmin/fileedit.php of the c… Ucms Mitigation only Fix from $2,3002023-03-09 HIGH 8.8 CVE-2022-42234 There is a file inclusion vulnerability in the template management module in UCMS 1.6 Ucms No fix yet Fix from $1,9502022-10-14 MEDIUM 6.1 CVE-2022-38527 UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page. Ucms No fix yet Fix from $1,6002022-09-19 CRITICAL 9.8 CVE-2022-38297 UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning. Ucms No fix yet Fix from $2,3002022-09-12 CRITICAL 9.8 CVE-2022-35426 UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. Ucms No fix yet Fix from $2,3002022-08-10 CRITICAL 9.1 CVE-2022-28443 UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability. Ucms No fix yet Fix from $2,3002022-04-21 HIGH 8.8 CVE-2022-28440 An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file. Ucms No fix yet Fix from $1,9502022-04-21 HIGH 7.5 CVE-2022-28444 UCMS v1.6 was discovered to contain an arbitrary file read vulnerability. Ucms No fix yet Fix from $1,9502022-04-21 MEDIUM 5.4 CVE-2020-20781 A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or … Ucms No fix yet Fix from $1,6002021-09-29 MEDIUM 5.3 CVE-2021-25809 UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php. Ucms No fix yet Fix from $1,6002021-07-23 CRITICAL 9.8 CVE-2020-25537 File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission. Ucms No fix yet Fix from $2,3002020-11-30 CRITICAL 9.8 CVE-2020-25483EPSS 9% An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the s… Ucms No fix yet Fix from $2,3002020-10-23 MEDIUM 5.3 CVE-2020-24981 An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an error message caused by dire… Ucms No fix yet Fix from $1,6002020-09-04 HIGH 8.8 CVE-2019-12251 sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter. Ucms No fix yet Fix from $1,9502019-05-21 MEDIUM 6.1 CVE-2018-16804 An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request. Ucms No fix yet Fix from $1,6002019-03-07 HIGH 8.8 CVE-2018-20598 UCMS 1.4.7 has ?do=user_addpost CSRF. Ucms No fix yet Fix from $1,9502018-12-30 HIGH 8.8 CVE-2018-20599 UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action. Ucms No fix yet Fix from $1,9502018-12-30 MEDIUM 6.1 CVE-2018-20600 sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action. Ucms No fix yet Fix from $1,6002018-12-30 HIGH 8.8 CVE-2018-19437 UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie … Ucms No fix yet Fix from $1,9502018-11-22 MEDIUM 6.1 CVE-2018-17320 An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action. Ucms Mitigation only Fix from $1,6002018-09-21 CRITICAL 9.8 CVE-2018-17035 UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter. Ucms No fix yet Fix from $2,3002018-09-14 CRITICAL 9.8 CVE-2018-17036 An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, … Ucms No fix yet Fix from $2,3002018-09-14 HIGH 8.8 CVE-2018-17037 user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3. Ucms No fix yet Fix from $1,9502018-09-14 MEDIUM 6.1 CVE-2018-17034 UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter. Ucms No fix yet Fix from $1,6002018-09-14