Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bitrix24 MEDIUM 6.8
CVE-2024-34885

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts pass…

No fix yet
Fix from $1,600 2024-11-04
Bitrix24 MEDIUM 6.8
CVE-2024-34891

Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account pa…

No fix yet
Fix from $1,600 2024-11-04
Bitrix24 CRITICAL 9.8
CVE-2023-1719

Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments…

No fix yet
Fix from $2,300 2023-11-01
Bitrix24 CRITICAL 9.6
CVE-2023-1716

Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victi…

No fix yet
Fix from $2,300 2023-11-01
Bitrix24 CRITICAL 9.6
CVE-2023-1717

Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execu…

No fix yet
Fix from $2,300 2023-11-01
Bitrix24 HIGH 8.8
CVE-2023-1714

Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to exec…

No fix yet
Fix from $1,950 2023-11-01
Bitrix24 HIGH 8.0
CVE-2023-1720

Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's bro…

No fix yet
Fix from $1,950 2023-11-01
Bitrix24 HIGH 7.5
CVE-2023-1718EPSS 24%

Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause den…

No fix yet
Fix from $1,950 2023-11-01
Bitrix24 MEDIUM 5.4
CVE-2023-1715

A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing …

No fix yet
Fix from $1,600 2023-11-01
Bitrix24 HIGH 8.8
CVE-2023-1713

Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote…

No fix yet
Fix from $1,950 2023-11-01
Bitrix Site Manager MEDIUM 5.4
CVE-2017-20122

A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of …

No fix yet
Fix from $1,600 2022-06-30
Bitrix24 CRITICAL 9.8
CVE-2022-27228EPSS 21%

In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code.

Fix: 21.0.100+
Fix from $2,300 2022-03-22
Bitrix Framework MEDIUM 6.5
CVE-2020-28206

An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentica…

No fix yet
Fix from $1,600 2020-12-02
Bitrix24 CRITICAL 9.8
CVE-2020-13484

Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destinat…

Fix: after 20.0.975
Fix from $2,300 2020-06-24
Bitrix24 MEDIUM 6.1
CVE-2020-13483

The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.ph…

Fix: after 20.0.0
Fix from $1,600 2020-06-24
Bitrix Site Manager MEDIUM 6.1
CVE-2008-2052

Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct p…

No fix yet
Fix from $1,600 2008-05-02