Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pwndoc MEDIUM 6.5
CVE-2025-27410

PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the T…

Fix: 1.2.0+
Fix from $1,600 2025-02-28
Pwndoc HIGH 8.1
CVE-2025-23044

PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behal…

Fix: 0.9.0+
Fix from $1,950 2025-01-20
Pwndoc MEDIUM 6.5
CVE-2024-55653

PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising a…

Fix: 0.9.0+
Fix from $1,600 2024-12-10
Pwndoc HIGH 8.5
CVE-2024-55602

PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update …

Fix: after 1.2.1
Fix from $1,950 2024-12-10
Pwndoc HIGH 8.8
CVE-2022-45771

An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted aud…

No fix yet
Fix from $1,950 2022-12-05
Pwndoc MEDIUM 5.3
CVE-2022-44022

PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings for authentication attempts.

Fix: after 0.5.3
Fix from $1,600 2022-10-30
Pwndoc MEDIUM 5.3
CVE-2022-44023

PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response messages for authentication attempts.

Fix: after 0.5.3
Fix from $1,600 2022-10-30
Pwndoc HIGH 8.8
CVE-2021-31590

PwnDoc all versions until 0.4.0 (2021-08-23) has incorrect JSON Webtoken handling, leading to incorrect access control. With a valid JSON Webtoken th…

Fix: 0.4.0+
Fix from $1,950 2021-07-19