Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tcexam MEDIUM 6.5
CVE-2023-6554

When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to d…

Fix: 15.1.0+
Fix from $1,600 2024-01-11
Tcexam MEDIUM 6.1
CVE-2021-20115

A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php …

Fix: after 14.8.3
Fix from $1,600 2021-08-05
Tcexam MEDIUM 6.1
CVE-2021-20116

A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile…

Fix: after 14.8.4
Fix from $1,600 2021-08-05
Tcexam HIGH 7.5
CVE-2021-20114EPSS 6%

When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, whi…

Fix: after 14.8.1
Fix from $1,950 2021-07-30
Tcexam MEDIUM 5.4
CVE-2021-20111

A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a…

Fix: after 14.8.1
Fix from $1,600 2021-07-30
Tcexam MEDIUM 5.4
CVE-2021-20112

A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining w…

Fix: after 14.8.1
Fix from $1,600 2021-07-30
Tcexam MEDIUM 5.3
CVE-2021-20113

An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not…

Fix: after 14.8.1
Fix from $1,600 2021-07-30
Tcexam HIGH 7.4
CVE-2020-5745

Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into click…

Patch available
Fix from $1,950 2020-05-07
Tcexam MEDIUM 6.1
CVE-2020-5748

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks …

Patch available
Fix from $1,600 2020-05-07
Tcexam MEDIUM 6.1
CVE-2020-5750

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks …

Patch available
Fix from $1,600 2020-05-07
Tcexam MEDIUM 5.4
CVE-2020-5746

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by…

Patch available
Fix from $1,600 2020-05-07
Tcexam MEDIUM 5.4
CVE-2020-5747

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by…

Patch available
Fix from $1,600 2020-05-07
Tcexam MEDIUM 5.4
CVE-2020-5749

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by…

Patch available
Fix from $1,600 2020-05-07
Tcexam MEDIUM 5.4
CVE-2020-5751

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by…

Patch available
Fix from $1,600 2020-05-07
Tcpdf CRITICAL 9.8
CVE-2018-17057EPSS 26%

An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.

Fix: 3.16.0 / 6.2.22+
Fix from $2,300 2018-09-14
Tcexam MEDIUM 6.1
CVE-2018-13422

TCExam before 14.1.2 has XSS via an ff_ or xl_ field.

Fix: 14.1.2+
Fix from $1,600 2018-07-07
Tcexam MEDIUM 6.0
CVE-2012-4601

Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to…

Fix: after 11.3.008
Fix from $1,600 2012-11-23
Tcexam MEDIUM 6.8
CVE-2012-4237

Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbi…

Fix: after 11.3.007
Fix from $1,600 2012-08-20
Tcexam MEDIUM 5.0
CVE-2011-3806

TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in a…

Mitigation only
Fix from $1,600 2011-09-24
Tcexam MEDIUM 6.8
CVE-2010-2153EPSS 7%

Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to exec…

No fix yet
Fix from $1,600 2010-06-03
Aiocp HIGH 7.5
CVE-2009-4747

PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to …

No fix yet
Fix from $1,950 2010-03-26
Aiocp HIGH 7.5
CVE-2009-3220

PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,950 2009-09-16