Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Maarch Rm HIGH 7.5
CVE-2022-37772

Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the applicatio…

Fix: 2.8.6+
Fix from $1,950 2022-11-23
Maarch Rm MEDIUM 6.5
CVE-2022-37773

An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the com…

Fix: 2.8.6+
Fix from $1,600 2022-11-23
Maarch Rm MEDIUM 5.3
CVE-2022-37774

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a…

Fix: 2.8.6+
Fix from $1,600 2022-11-23
Maarch Rm CRITICAL 9.1
CVE-2019-15855

An issue was discovered in Maarch RM before 2.5. A path traversal vulnerability allows an unauthenticated remote attacker to overwrite any files with…

Fix: 2.5+
Fix from $2,300 2020-01-17
Maarch Rm HIGH 8.8
CVE-2019-15854

An issue was discovered in Maarch RM before 2.5. A privilege escalation vulnerability allows an authenticated user with lowest privileges to give her…

Fix: 2.5+
Fix from $1,950 2020-01-17
Gec\/ged HIGH 7.5
CVE-2015-1587EPSS 44%

Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote attackers t…

Fix: after 2.8
Fix from $1,950 2015-02-19
Letterbox MEDIUM 5.0
CVE-2014-8995

SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.

No fix yet
Fix from $1,600 2014-11-20