Vulnerability index

Browse CVEs

29 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2024-47532 RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensibl… Restrictedpython 7.3+ Fix from $1,6002024-09-30 CRITICAL 9.8 CVE-2024-24811 SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbit… Sqlalchemyda 2.2+ Fix from $2,3002024-02-07 MEDIUM 5.4 CVE-2023-42458 Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG image… Zope 4.8.10 / 5.8.5+ Fix from $1,6002023-09-21 HIGH 7.7 CVE-2023-41050 AccessControl provides a general security framework for use in Zope. Python's "format" functionality allows someone controlling the format string to … Accesscontrol 4.4 / 4.8.9+ Fix from $1,9502023-09-06 HIGH 7.7 CVE-2023-41039 RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling t… Restrictedpython 5.4 / 6.2+ Fix from $1,9502023-08-30 CRITICAL 9.9 CVE-2023-37271 RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environm… Restrictedpython 5.3+ Fix from $2,3002023-07-11 HIGH 7.5 CVE-2023-36814 Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's marshal module to handle uncheck… Products.cmfcore 3.2+ Fix from $1,9502023-07-03 HIGH 7.2 CVE-2021-32811 Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to… Accesscontrol 4.3 / 4.6.3+ Fix from $1,9502021-08-02 HIGH 7.2 CVE-2021-32807 The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code th… Accesscontrol 4.3 / 5.2+ Fix from $1,9502021-07-30 HIGH 7.8 CVE-2021-36089 Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::app… Grok after 9.2.0 Fix from $1,9502021-07-01 HIGH 8.8 CVE-2021-32674 Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefoundation/Zope/security/advisor… Zope 4.6.1 / 5.2.1+ Fix from $1,9502021-06-08 MEDIUM 5.3 CVE-2021-21360 Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSet… Products.genericsetup 2.1.1+ Fix from $1,6002021-03-09 MEDIUM 6.5 CVE-2021-21336 Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 t… Products.pluggableauthservice 2.6.0+ Fix from $1,6002021-03-08 MEDIUM 6.1 CVE-2021-21337EPSS 8% Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 t… Products.pluggableauthservice 2.6.1+ Fix from $1,6002021-03-08 MEDIUM 6.1 CVE-2011-4924 Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x be… Zope 2.8.12 / 2.9.12+ Fix from $1,6002019-11-25 MEDIUM 6.1 CVE-2009-5145 Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4… Zope Patch available Fix from $1,6002017-08-07 MEDIUM 6.0 CVE-2009-2701 Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x… Zodb Patch available Fix from $1,6002009-09-08 HIGH 7.5 CVE-2009-0669 Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass a… Zodb after 3.8.1 Fix from $1,9502009-08-07 MEDIUM 6.5 CVE-2009-0668 Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows… Zodb after 3.8.1 Fix from $1,6002009-08-07 MEDIUM 5.0 CVE-2006-4684 The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) marku… Zope Patch available Fix from $1,6002006-09-19 HIGH 7.5 CVE-2002-0688 ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and ca… Zope Patch available Fix from $1,9502002-07-23 MEDIUM 5.0 CVE-2002-0687 The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers. Zope after 2.5.1b1 Fix from $1,6002002-07-23 HIGH 7.5 CVE-2002-0170 Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violat… Zope Patch available Fix from $1,9502002-04-22 HIGH 7.5 CVE-2001-1227 Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute o… Zope Patch available Fix from $1,9502001-10-10 HIGH 7.5 CVE-2001-1278 Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute o… Zope Patch available Fix from $1,9502001-10-10 MEDIUM 5.0 CVE-2000-1212 Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privile… Zope Patch available Fix from $1,6002000-12-18 HIGH 7.5 CVE-2000-1211 Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which c… Zope Patch available Fix from $1,9502000-12-16 HIGH 7.2 CVE-2000-0725 Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying … Zope Patch available Fix from $1,9502000-10-20 HIGH 10.0 CVE-2000-0062 The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities. Zope No fix yet Fix from $1,9502000-01-04