Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sage Dpw HIGH 7.5
CVE-2025-67805

A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposi…

Mitigation only
Fix from $1,950 2026-04-01
Sage Dpw MEDIUM 5.3
CVE-2025-67806

The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in…

Mitigation only
Fix from $1,600 2026-04-01
Sage Dpw MEDIUM 5.3
CVE-2025-51533

An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a cr…

Fix: 2025_06_000+
Fix from $1,600 2025-08-07
Sage Dpw HIGH 7.5
CVE-2025-51532

Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted requ…

Fix: 2025_06_000+
Fix from $1,950 2025-08-06
Sage Dpw MEDIUM 6.1
CVE-2025-51531

A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arbitrary JavaScript in the cont…

Fix: 2025_06_000+
Fix from $1,600 2025-08-06
Sage Dpw HIGH 8.1
CVE-2024-56883

Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the serv…

Fix: 2024_12_001+
Fix from $1,950 2025-02-18
Sage Dpw MEDIUM 5.4
CVE-2024-56882

Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role privileges can permanently stor…

Fix: 2024_12_000+
Fix from $1,600 2025-02-18
Sage Dpw MEDIUM 6.1
CVE-2020-26583

An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (in a file) via the expenses c…

Fix: 2020_06_002+
Fix from $1,600 2020-10-16
Sage Dpw MEDIUM 6.1
CVE-2020-26584

An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. The search field "Kurs suchen" on the page Kurskatalog is vulnerable to Reflected X…

Fix: 2020_06_002+
Fix from $1,600 2020-10-16