Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cells MEDIUM 6.5
CVE-2021-41324

Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cel…

Mitigation only
Fix from $1,600 2021-09-30
Cells MEDIUM 6.5
CVE-2021-41323

Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells files belong…

Mitigation only
Fix from $1,600 2021-09-30
Cells MEDIUM 6.5
CVE-2021-41325

Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile parameter. (In ad…

Mitigation only
Fix from $1,600 2021-09-30
Cells HIGH 7.0
CVE-2020-12850

The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as v…

No fix yet
Fix from $1,950 2020-06-11
Cells MEDIUM 5.4
CVE-2020-12848

In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shared user account is created in …

No fix yet
Fix from $1,600 2020-06-05
Cells MEDIUM 5.4
CVE-2020-12849

Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user roles. These profile pictures …

No fix yet
Fix from $1,600 2020-06-05
Cells HIGH 8.1
CVE-2020-12851

Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by up…

No fix yet
Fix from $1,950 2020-06-04
Cells HIGH 7.2
CVE-2020-12847

Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role. This …

No fix yet
Fix from $1,950 2020-06-04
Cells MEDIUM 6.8
CVE-2020-12852

The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the download…

No fix yet
Fix from $1,600 2020-06-04
Cells MEDIUM 6.1
CVE-2020-12853

Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to…

No fix yet
Fix from $1,600 2020-06-04
Pydio HIGH 7.7
CVE-2019-15033

Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to ind…

No fix yet
Fix from $1,950 2019-09-19
Pydio MEDIUM 5.3
CVE-2019-15032

Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhos…

No fix yet
Fix from $1,600 2019-09-19
Pydio MEDIUM 5.3
CVE-2019-10046

An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information.

No fix yet
Fix from $1,600 2019-05-31