Vulnerability index

Browse CVEs

29 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Restrictedpython MEDIUM 6.5
CVE-2024-47532

RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensibl…

Fix: 7.3+
Fix from $1,600 2024-09-30
Sqlalchemyda CRITICAL 9.8
CVE-2024-24811

SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbit…

Fix: 2.2+
Fix from $2,300 2024-02-07
Zope MEDIUM 5.4
CVE-2023-42458

Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG image…

Fix: 4.8.10 / 5.8.5+
Fix from $1,600 2023-09-21
Accesscontrol HIGH 7.7
CVE-2023-41050

AccessControl provides a general security framework for use in Zope. Python's "format" functionality allows someone controlling the format string to …

Fix: 4.4 / 4.8.9+
Fix from $1,950 2023-09-06
Restrictedpython HIGH 7.7
CVE-2023-41039

RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling t…

Fix: 5.4 / 6.2+
Fix from $1,950 2023-08-30
Restrictedpython CRITICAL 9.9
CVE-2023-37271

RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environm…

Fix: 5.3+
Fix from $2,300 2023-07-11
Products.cmfcore HIGH 7.5
CVE-2023-36814

Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's marshal module to handle uncheck…

Fix: 3.2+
Fix from $1,950 2023-07-03
Accesscontrol HIGH 7.2
CVE-2021-32811

Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to…

Fix: 4.3 / 4.6.3+
Fix from $1,950 2021-08-02
Accesscontrol HIGH 7.2
CVE-2021-32807

The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code th…

Fix: 4.3 / 5.2+
Fix from $1,950 2021-07-30
Grok HIGH 7.8
CVE-2021-36089

Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::app…

Fix: after 9.2.0
Fix from $1,950 2021-07-01
Zope HIGH 8.8
CVE-2021-32674

Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefoundation/Zope/security/advisor…

Fix: 4.6.1 / 5.2.1+
Fix from $1,950 2021-06-08
Products.genericsetup MEDIUM 5.3
CVE-2021-21360

Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSet…

Fix: 2.1.1+
Fix from $1,600 2021-03-09
Products.pluggableauthservice MEDIUM 6.5
CVE-2021-21336

Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 t…

Fix: 2.6.0+
Fix from $1,600 2021-03-08
Products.pluggableauthservice MEDIUM 6.1
CVE-2021-21337EPSS 8%

Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 t…

Fix: 2.6.1+
Fix from $1,600 2021-03-08
Zope MEDIUM 6.1
CVE-2011-4924

Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x be…

Fix: 2.8.12 / 2.9.12+
Fix from $1,600 2019-11-25
Zope MEDIUM 6.1
CVE-2009-5145

Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4…

Patch available
Fix from $1,600 2017-08-07
Zodb MEDIUM 6.0
CVE-2009-2701

Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x…

Patch available
Fix from $1,600 2009-09-08
Zodb HIGH 7.5
CVE-2009-0669

Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass a…

Fix: after 3.8.1
Fix from $1,950 2009-08-07
Zodb MEDIUM 6.5
CVE-2009-0668

Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows…

Fix: after 3.8.1
Fix from $1,600 2009-08-07
Zope MEDIUM 5.0
CVE-2006-4684

The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) marku…

Patch available
Fix from $1,600 2006-09-19
Zope HIGH 7.5
CVE-2002-0688

ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and ca…

Patch available
Fix from $1,950 2002-07-23
Zope MEDIUM 5.0
CVE-2002-0687

The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.

Fix: after 2.5.1b1
Fix from $1,600 2002-07-23
Zope HIGH 7.5
CVE-2002-0170

Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violat…

Patch available
Fix from $1,950 2002-04-22
Zope HIGH 7.5
CVE-2001-1227

Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute o…

Patch available
Fix from $1,950 2001-10-10
Zope HIGH 7.5
CVE-2001-1278

Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute o…

Patch available
Fix from $1,950 2001-10-10
Zope MEDIUM 5.0
CVE-2000-1212

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privile…

Patch available
Fix from $1,600 2000-12-18
Zope HIGH 7.5
CVE-2000-1211

Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which c…

Patch available
Fix from $1,950 2000-12-16
Zope HIGH 7.2
CVE-2000-0725

Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying …

Patch available
Fix from $1,950 2000-10-20
Zope HIGH 10.0
CVE-2000-0062

The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.

No fix yet
Fix from $1,950 2000-01-04