Записи ONLYOFFICE
31 опубликованных записей вендора onlyoffice.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-787 Out-of-bounds Write4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-20 Improper Input Validation3
- CWE-287 Improper Authentication2
- CWE-427 Uncontrolled Search Path Element1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
31 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-2021-25833Эксплойта нет | A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21.onlyoffice · document server · CWE-22 | Критическая9,8 | — | 43,5 % | 1 мар. 2021 г. |
43В плане | CVE-2021-25832Эксплойта нет | A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0.onlyoffice · document server · CWE-787 | Критическая9,8 | — | 12,6 % | 1 мар. 2021 г. |
43В плане | CVE-2021-25830Эксплойта нет | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13.onlyoffice · document server | Критическая9,8 | — | 11,8 % | 1 мар. 2021 г. |
42В плане | CVE-2021-25831Эксплойта нет | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.onlyoffice · document server | Критическая9,8 | — | 11,5 % | 1 мар. 2021 г. |
41В плане | CVE-2021-3199Эксплойта нет | Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /..onlyoffice · document server · CWE-22 | Критическая9,8 | — | 8,2 % | 26 янв. 2021 г. |
41В плане | CVE-2022-29776Эксплойта нет | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component Desktoonlyoffice · core · CWE-787 | Критическая9,8 | — | 6,9 % | 2 июн. 2022 г. |
41В плане | CVE-2022-29777Эксплойта нет | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component Desktoponlyoffice · core · CWE-787 | Критическая9,8 | — | 6,9 % | 2 июн. 2022 г. |
41В плане | CVE-2023-34939Эксплойта нет | Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProonlyoffice · onlyoffice · CWE-22 | Критическая9,8 | — | 5,0 % | 22 июн. 2023 г. |
40В плане | CVE-2020-11536Эксплойта нет | An issue was discovered in ONLYOFFICE Document Server 5.5.0.onlyoffice · document server · CWE-20 | Критическая9,8 | — | 2,6 % | 15 апр. 2020 г. |
40В плане | CVE-2023-30187Эксплойта нет | An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code onlyoffice · document server · CWE-787 | Критическая9,8 | — | 2,4 % | 14 авг. 2023 г. |
40В плане | CVE-2020-11535Эксплойта нет | An issue was discovered in ONLYOFFICE Document Server 5.5.0.onlyoffice · document server · CWE-91 | Критическая9,8 | — | 2,3 % | 15 апр. 2020 г. |
40В плане | CVE-2021-40864Эксплойта нет | The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.onlyoffice · google translate | Критическая9,8 | — | 2,3 % | 10 сент. 2021 г. |
40В плане | CVE-2023-30186Эксплойта нет | A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via craftedonlyoffice · document server · CWE-416 | Критическая9,8 | — | 2,3 % | 14 авг. 2023 г. |
40В плане | CVE-2020-11534Эксплойта нет | An issue was discovered in ONLYOFFICE Document Server 5.5.0.onlyoffice · document server · CWE-20 | Критическая9,8 | — | 2,2 % | 15 апр. 2020 г. |
40В плане | CVE-2021-43445Эксплойта нет | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.onlyoffice · server · CWE-287 | Критическая9,8 | — | 1,7 % | 23 янв. 2023 г. |
39Наблюдать | CVE-2020-11537Эксплойта нет | A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0.onlyoffice · document server · CWE-89 | Критическая9,8 | — | 1,5 % | 15 апр. 2020 г. |
32Наблюдать | CVE-2021-25829Эксплойта нет | An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.onlyoffice · document server | Высокая7,5 | — | 7,4 % | 1 мар. 2021 г. |
32Наблюдать | CVE-2021-43449Эксплойта нет | ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF).onlyoffice · server · CWE-918 | Высокая8,1 | — | 1,2 % | 23 янв. 2023 г. |
31Наблюдать | CVE-2023-30188Эксплойта нет | Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via conlyoffice · document server · CWE-835 | Высокая7,5 | — | 2,2 % | 14 авг. 2023 г. |
31Наблюдать | CVE-2022-48422Эксплойта нет | ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the curonlyoffice · document server · CWE-427 | Высокая7,8 | — | 0,3 % | 18 мар. 2023 г. |
30Наблюдать | CVE-2021-43447Эксплойта нет | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.onlyoffice · server · CWE-306 | Высокая7,5 | — | 1,3 % | 23 янв. 2023 г. |
30Наблюдать | CVE-2021-43444Эксплойта нет | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.onlyoffice · server · CWE-287 | Высокая7,5 | — | 1,2 % | 23 янв. 2023 г. |
26Наблюдать | CVE-2023-46988Proof of concept | Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating thonlyoffice · document server · CWE-22 | Средняя6,7 | — | 0,5 % | 1 апр. 2025 г. |
25Наблюдать | CVE-2022-24229Эксплойта нет | A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTMLonlyoffice · document server · CWE-79 | Средняя6,1 | — | 1,9 % | 8 апр. 2022 г. |
24Наблюдать | CVE-2021-43446Эксплойта нет | ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS).onlyoffice · server · CWE-79 | Средняя6,1 | — | 0,8 % | 23 янв. 2023 г. |
- CVE-2021-2583352В плане
A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21.
КритическаяCVSS 9,8Эксплойта нетEPSS 44 %onlyoffice · document server1 мар. 2021 г.
- CVE-2021-2583243В плане
A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 13 %onlyoffice · document server1 мар. 2021 г.
- CVE-2021-2583043В плане
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13.
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %onlyoffice · document server1 мар. 2021 г.
- CVE-2021-2583142В плане
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %onlyoffice · document server1 мар. 2021 г.
- CVE-2021-319941В плане
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /..
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %onlyoffice · document server26 янв. 2021 г.
- CVE-2022-2977641В плане
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component Deskto
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %onlyoffice · core2 июн. 2022 г.
- CVE-2022-2977741В плане
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component Desktop
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %onlyoffice · core2 июн. 2022 г.
- CVE-2023-3493941В плане
Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadPro
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %onlyoffice · onlyoffice22 июн. 2023 г.
- CVE-2020-1153640В плане
An issue was discovered in ONLYOFFICE Document Server 5.5.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %onlyoffice · document server15 апр. 2020 г.
- CVE-2023-3018740В плане
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %onlyoffice · document server14 авг. 2023 г.
- CVE-2020-1153540В плане
An issue was discovered in ONLYOFFICE Document Server 5.5.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %onlyoffice · document server15 апр. 2020 г.
- CVE-2021-4086440В плане
The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %onlyoffice · google translate10 сент. 2021 г.
- CVE-2023-3018640В плане
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %onlyoffice · document server14 авг. 2023 г.
- CVE-2020-1153440В плане
An issue was discovered in ONLYOFFICE Document Server 5.5.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %onlyoffice · document server15 апр. 2020 г.
- CVE-2021-4344540В плане
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %onlyoffice · server23 янв. 2023 г.
- CVE-2020-1153739Наблюдать
A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %onlyoffice · document server15 апр. 2020 г.
- CVE-2021-2582932Наблюдать
An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %onlyoffice · document server1 мар. 2021 г.
- CVE-2021-4344932Наблюдать
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF).
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %onlyoffice · server23 янв. 2023 г.
- CVE-2023-3018831Наблюдать
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via c
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %onlyoffice · document server14 авг. 2023 г.
- CVE-2022-4842231Наблюдать
ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the cur
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %onlyoffice · document server18 мар. 2023 г.
- CVE-2021-4344730Наблюдать
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %onlyoffice · server23 янв. 2023 г.
- CVE-2021-4344430Наблюдать
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %onlyoffice · server23 янв. 2023 г.
- CVE-2023-4698826Наблюдать
Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating th
СредняяCVSS 6,7Proof of conceptEPSS 1 %onlyoffice · document server1 апр. 2025 г.
- CVE-2022-2422925Наблюдать
A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML
СредняяCVSS 6,1Эксплойта нетEPSS 2 %onlyoffice · document server8 апр. 2022 г.
- CVE-2021-4344624Наблюдать
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS).
СредняяCVSS 6,1Эксплойта нетEPSS 1 %onlyoffice · server23 янв. 2023 г.