Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cipace HIGH 8.8
CVE-2024-50619

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A…

Fix: 9.17+
Fix from $1,950 2026-02-11
Cipace HIGH 7.5
CVE-2024-50617

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files.…

Fix: 9.17+
Fix from $1,950 2026-02-11
Cipace HIGH 8.8
CVE-2024-50620

Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce bef…

Fix: 9.17+
Fix from $1,950 2026-02-11
Cipace CRITICAL 9.8
CVE-2020-11586

An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XM…

Fix: 9.1+
Fix from $2,300 2020-04-06
Cipace HIGH 7.5
CVE-2020-11587

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the content of ETL Pro…

Fix: 9.1+
Fix from $1,950 2020-04-06
Cipace CRITICAL 9.8
CVE-2020-11597

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request and inject SQL statement…

Fix: 9.1+
Fix from $2,300 2020-04-06
Cipace CRITICAL 9.8
CVE-2020-11598

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and exe…

Fix: 9.1+
Fix from $2,300 2020-04-06
Cipace HIGH 7.5
CVE-2020-11589

An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET reques…

Fix: 9.1+
Fix from $1,950 2020-04-06
Cipace HIGH 7.5
CVE-2020-11592

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the columns of a speci…

Fix: 9.1+
Fix from $1,950 2020-04-06
Cipace HIGH 7.5
CVE-2020-11593

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data …

Fix: 9.1+
Fix from $1,950 2020-04-06
Cipace HIGH 7.5
CVE-2020-11594

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that causes a stack error to b…

Fix: 9.1+
Fix from $1,950 2020-04-06
Cipace HIGH 7.5
CVE-2020-11595

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the upload folder p…

Fix: 9.1+
Fix from $1,950 2020-04-06
Cipace HIGH 7.5
CVE-2020-11596

A Directory Traversal issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make HTTP GET requests to a cer…

Fix: 9.1+
Fix from $1,950 2020-04-06
Cipace HIGH 7.5
CVE-2020-11599

An issue was discovered in CIPPlanner CIPAce 6.80 Build 2016031401. GetDistributedPOP3 allows attackers to obtain the username and password of the SM…

Fix: 9.1+
Fix from $1,950 2020-04-06
Cipace MEDIUM 5.3
CVE-2020-11590

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to HealthPage.aspx and ob…

Fix: 9.1+
Fix from $1,600 2020-04-06
Cipace MEDIUM 5.3
CVE-2020-11591

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the full applicatio…

Fix: 9.1+
Fix from $1,600 2020-04-06
Cipace MEDIUM 5.3
CVE-2020-11588

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to two files that contain…

Fix: 9.1+
Fix from $1,600 2020-04-06