Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rukovoditel HIGH 8.8
CVE-2023-53913

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attac…

No fix yet
Fix from $1,950 2025-12-17
Rukovoditel MEDIUM 5.4
CVE-2023-53898

Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers ca…

No fix yet
Fix from $1,600 2025-12-16
Rukovoditel MEDIUM 5.4
CVE-2023-53897

Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attac…

No fix yet
Fix from $1,600 2025-12-16
Rukovoditel HIGH 7.1
CVE-2024-34469

Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

Fix: 3.5.3+
Fix from $1,950 2024-05-04
Rukovoditel MEDIUM 6.1
CVE-2024-34468

Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.

Fix: 3.5.3+
Fix from $1,600 2024-05-04
Rukovoditel CRITICAL 9.8
CVE-2022-48175

Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/aja…

No fix yet
Fix from $2,300 2023-01-30
Rukovoditel HIGH 8.8
CVE-2022-45020

Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=user…

No fix yet
Fix from $1,950 2022-12-05
Rukovoditel CRITICAL 9.8
CVE-2022-44945

Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.

Mitigation only
Fix from $2,300 2022-12-02
Rukovoditel MEDIUM 5.4
CVE-2022-44944

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=…

No fix yet
Fix from $1,600 2022-12-02
Rukovoditel MEDIUM 5.4
CVE-2022-44946

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pag…

No fix yet
Fix from $1,600 2022-12-02
Rukovoditel MEDIUM 5.4
CVE-2022-44947

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=enti…

No fix yet
Fix from $1,600 2022-12-02
Rukovoditel MEDIUM 5.4
CVE-2022-44948

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=enti…

No fix yet
Fix from $1,600 2022-12-02
Rukovoditel MEDIUM 5.4
CVE-2022-44949

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=ent…

No fix yet
Fix from $1,600 2022-12-02
Rukovoditel MEDIUM 5.4
CVE-2022-44950

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=ent…

No fix yet
Fix from $1,600 2022-12-02
Rukovoditel MEDIUM 5.4
CVE-2022-44951

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=…

No fix yet
Fix from $1,600 2022-12-02
Rukovoditel MEDIUM 5.4
CVE-2022-44952

Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=configuration/application. This v…

No fix yet
Fix from $1,600 2022-12-02
Rukovoditel HIGH 8.8
CVE-2022-43288

Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/index.php?module=logs/view&type…

No fix yet
Fix from $1,950 2022-11-14
Rukovoditel CRITICAL 9.8
CVE-2022-43168

Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.

No fix yet
Fix from $2,300 2022-10-28
Rukovoditel MEDIUM 5.4
CVE-2022-43165

A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1 allows a…

No fix yet
Fix from $1,600 2022-10-28
Rukovoditel MEDIUM 5.4
CVE-2022-43166

A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1 allows a…

No fix yet
Fix from $1,600 2022-10-28
Rukovoditel MEDIUM 5.4
CVE-2022-43167

A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel v3.2.1 all…

No fix yet
Fix from $1,600 2022-10-28
Rukovoditel MEDIUM 5.4
CVE-2022-43169

A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.…

No fix yet
Fix from $1,600 2022-10-28
Rukovoditel MEDIUM 5.4
CVE-2022-43170

A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel …

No fix yet
Fix from $1,600 2022-10-28
Rukovoditel MEDIUM 5.4
CVE-2022-43164

A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 allows aut…

No fix yet
Fix from $1,600 2022-10-28
Rukovoditel MEDIUM 5.4
CVE-2022-43185

A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary we…

No fix yet
Fix from $1,600 2022-10-19
Rukovoditel HIGH 7.2
CVE-2020-13590

Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially c…

No fix yet
Fix from $1,950 2022-04-18
Rukovoditel MEDIUM 5.4
CVE-2020-18469

Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel…

No fix yet
Fix from $1,600 2021-08-26
Rukovoditel MEDIUM 5.4
CVE-2020-18470

Stored cross-site scripting (XSS) vulnerability in the Name of application field found in the General Configuration page in Rukovoditel 2.4.1 allows …

No fix yet
Fix from $1,600 2021-08-26
Rukovoditel HIGH 8.8
CVE-2020-13588

An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id…

No fix yet
Fix from $1,950 2021-08-17
Rukovoditel HIGH 8.8
CVE-2020-13589

An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The entities_id para…

No fix yet
Fix from $1,950 2021-08-17