Vulnerability index

Browse CVEs

81 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webmin MEDIUM 6.1
CVE-2023-38309

An issue was discovered in Webmin 2.021. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the package search functionality. The…

No fix yet
Fix from $1,600 2023-07-31
Webmin MEDIUM 5.4
CVE-2023-38303

An issue was discovered in Webmin 2.021. One can exploit a stored Cross-Site Scripting (XSS) attack to achieve Remote Command Execution (RCE) through…

No fix yet
Fix from $1,600 2023-07-31
Webmin MEDIUM 5.4
CVE-2023-38304

An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users and Groups functionality, allo…

No fix yet
Fix from $1,600 2023-07-31
Webmin MEDIUM 5.4
CVE-2023-38307

An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users and Groups functionality. The …

No fix yet
Fix from $1,600 2023-07-31
Webmin MEDIUM 5.4
CVE-2023-38310

An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the configuration settings of the system…

No fix yet
Fix from $1,600 2023-07-31
Webmin MEDIUM 5.4
CVE-2023-38311

An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the System Logs Viewer functionality. Th…

No fix yet
Fix from $1,600 2023-07-31
Webmin MEDIUM 6.1
CVE-2022-3844

A vulnerability, which was classified as problematic, was found in Webmin 2.001. Affected is an unknown function of the file xterm/index.cgi. The man…

Patch available
Fix from $1,600 2022-11-02
Usermin HIGH 8.8
CVE-2022-35132

Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.

Fix: after 1.850
Fix from $1,950 2022-10-25
Usermin MEDIUM 6.1
CVE-2022-36880

The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.

Fix: after 1.850
Fix from $1,600 2022-07-27
Webmin CRITICAL 9.8
CVE-2022-36446EPSS 96%

software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

Fix: 1.997+
Fix from $2,300 2022-07-25
Webmin HIGH 8.8
CVE-2022-30708

Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virt…

Fix: after 1.991
Fix from $1,950 2022-05-15
Webmin CRITICAL 9.6
CVE-2021-32157

A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

No fix yet
Fix from $2,300 2022-04-11
Webmin HIGH 8.8
CVE-2021-32156

A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

No fix yet
Fix from $1,950 2022-04-11
Webmin HIGH 8.8
CVE-2021-32159

A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.

No fix yet
Fix from $1,950 2022-04-11
Webmin HIGH 8.8
CVE-2021-32162

A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.

No fix yet
Fix from $1,950 2022-04-11
Webmin MEDIUM 6.1
CVE-2021-32158

A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.

No fix yet
Fix from $1,600 2022-04-11
Webmin MEDIUM 6.1
CVE-2021-32160

A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.

No fix yet
Fix from $1,600 2022-04-11
Webmin MEDIUM 6.1
CVE-2021-32161

A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature.

No fix yet
Fix from $1,600 2022-04-11
Webmin HIGH 8.8
CVE-2022-0824EPSS 97%

Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

Fix: 1.990+
Fix from $1,950 2022-03-02
Webmin HIGH 8.1
CVE-2022-0829

Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

Fix: 1.990+
Fix from $1,950 2022-03-02
Webmin CRITICAL 9.6
CVE-2021-31761EPSS 34%

Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process feature.

No fix yet
Fix from $2,300 2021-04-25
Webmin HIGH 8.8
CVE-2021-31760EPSS 8%

Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process feature.

No fix yet
Fix from $1,950 2021-04-25
Webmin HIGH 8.8
CVE-2021-31762EPSS 9%

Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse …

No fix yet
Fix from $1,950 2021-04-25
Webmin CRITICAL 9.8
CVE-2020-35769

miniserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.

Patch available
Fix from $2,300 2020-12-29
Webmin HIGH 8.8
CVE-2020-35606EPSS 28%

Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with…

Fix: after 1.962
Fix from $1,950 2020-12-21
Webmin MEDIUM 6.1
CVE-2020-12670

XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML em…

Fix: after 1.941
Fix from $1,600 2020-10-12
Webmin MEDIUM 5.4
CVE-2020-8820

An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint. A user may enter any XSS Payload into the Comm…

Fix: after 1.941
Fix from $1,600 2020-10-12
Webmin MEDIUM 5.4
CVE-2020-8821EPSS 80%

An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into th…

Fix: after 1.941
Fix from $1,600 2020-10-12
Webmin HIGH 8.8
CVE-2019-15642EPSS 35%

rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call.…

Fix: after 1.920
Fix from $1,950 2019-08-26
Webmin MEDIUM 6.5
CVE-2019-15641

xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.

Fix: after 1.930
Fix from $1,600 2019-08-26