Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Qdpm HIGH 8.2
CVE-2019-25669

qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_ext…

Fix: after 9.1
Fix from $1,950 2026-04-05
Qdpm HIGH 8.2
CVE-2018-25208

qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through …

Fix: after 9.1
Fix from $1,950 2026-03-26
Qdpm CRITICAL 9.8
CVE-2023-45856

qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.

No fix yet
Fix from $2,300 2023-10-14
Qdpm HIGH 7.5
CVE-2023-45855

qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.

No fix yet
Fix from $1,950 2023-10-14
Qdpm HIGH 8.8
CVE-2022-26180

qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.

No fix yet
Fix from $1,950 2022-04-08
Qdpm MEDIUM 6.1
CVE-2020-19515

qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php.

No fix yet
Fix from $1,600 2021-09-09
Qdpm MEDIUM 5.4
CVE-2020-18468

Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted we…

No fix yet
Fix from $1,600 2021-08-26
Qdpm HIGH 8.8
CVE-2020-26165

qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php beca…

Fix: after 9.1
Fix from $1,950 2020-12-31
Qdpm MEDIUM 5.4
CVE-2020-26166

The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTM…

Mitigation only
Fix from $1,600 2020-10-05
Qdpm CRITICAL 9.8
CVE-2020-11811

In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type va…

No fix yet
Fix from $2,300 2020-04-16
Qdpm MEDIUM 5.4
CVE-2020-11814

A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious websites.

No fix yet
Fix from $1,600 2020-04-16
Qdpm HIGH 8.8
CVE-2020-7246EPSS 83%

A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo fu…

Fix: after 9.1
Fix from $1,950 2020-01-21
Qdpm MEDIUM 6.1
CVE-2019-8391

qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.

No fix yet
Fix from $1,600 2019-05-14
Qdpm MEDIUM 6.1
CVE-2019-8390EPSS 10%

qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.

No fix yet
Fix from $1,600 2019-05-14
Qdpm HIGH 8.8
CVE-2015-3884EPSS 14%

Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pa…

Fix: after 9.1
Fix from $1,950 2017-03-17
Qdpm HIGH 7.5
CVE-2015-3881

Information disclosure issue in qdPM 8.3 allows remote attackers to obtain sensitive information via a direct request to (1) core/config/databases.ym…

No fix yet
Fix from $1,950 2017-03-17
Qdpm MEDIUM 6.1
CVE-2015-3883

Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) search[keyw…

No fix yet
Fix from $1,600 2017-03-17
Qdpm MEDIUM 5.3
CVE-2015-3882

qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation…

No fix yet
Fix from $1,600 2017-03-17