Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Syspass MEDIUM 6.5
CVE-2025-25478

The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disc…

Fix: after 3.2.11
Fix from $1,600 2025-02-28
Syspass MEDIUM 5.4
CVE-2025-25476

A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript c…

Fix: after 3.2.11
Fix from $1,600 2025-02-28
Syspass HIGH 8.1
CVE-2025-25477

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed …

Fix: after 3.2.11
Fix from $1,950 2025-02-28
Syspass MEDIUM 6.1
CVE-2024-42904

A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload…

Fix: after 3.2.11
Fix from $1,600 2024-09-03
Syspass MEDIUM 5.4
CVE-2022-4930

A vulnerability classified as problematic was found in nuxsmin sysPass up to 3.2.4. Affected by this vulnerability is an unknown functionality of the…

Fix: after 3.2.4
Fix from $1,600 2023-03-06
Syspass MEDIUM 6.1
CVE-2017-9306

inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring i…

No fix yet
Fix from $1,600 2017-05-31
Syspass HIGH 7.5
CVE-2017-5999

An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers. The fact that inc/SP/Core…

Patch available
Fix from $1,950 2017-03-06