Перейти к содержимому
Noroxi

Записи ONLYOFFICE

31 опубликованных записей вендора onlyoffice.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
9
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

31 записей
  • CVE-2021-25833
    52В плане

    A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21.

    КритическаяCVSS 9,8Эксплойта нетEPSS 44 %

    onlyoffice · document server1 мар. 2021 г.

  • CVE-2021-25832
    43В плане

    A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 13 %

    onlyoffice · document server1 мар. 2021 г.

  • CVE-2021-25830
    43В плане

    A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13.

    КритическаяCVSS 9,8Эксплойта нетEPSS 12 %

    onlyoffice · document server1 мар. 2021 г.

  • CVE-2021-25831
    42В плане

    A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.

    КритическаяCVSS 9,8Эксплойта нетEPSS 12 %

    onlyoffice · document server1 мар. 2021 г.

  • CVE-2021-3199
    41В плане

    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /..

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    onlyoffice · document server26 янв. 2021 г.

  • CVE-2022-29776
    41В плане

    Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component Deskto

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    onlyoffice · core2 июн. 2022 г.

  • CVE-2022-29777
    41В плане

    Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component Desktop

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    onlyoffice · core2 июн. 2022 г.

  • CVE-2023-34939
    41В плане

    Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadPro

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    onlyoffice · onlyoffice22 июн. 2023 г.

  • CVE-2020-11536
    40В плане

    An issue was discovered in ONLYOFFICE Document Server 5.5.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    onlyoffice · document server15 апр. 2020 г.

  • CVE-2023-30187
    40В плане

    An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    onlyoffice · document server14 авг. 2023 г.

  • CVE-2020-11535
    40В плане

    An issue was discovered in ONLYOFFICE Document Server 5.5.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    onlyoffice · document server15 апр. 2020 г.

  • CVE-2021-40864
    40В плане

    The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    onlyoffice · google translate10 сент. 2021 г.

  • CVE-2023-30186
    40В плане

    A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    onlyoffice · document server14 авг. 2023 г.

  • CVE-2020-11534
    40В плане

    An issue was discovered in ONLYOFFICE Document Server 5.5.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    onlyoffice · document server15 апр. 2020 г.

  • CVE-2021-43445
    40В плане

    ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    onlyoffice · server23 янв. 2023 г.

  • CVE-2020-11537
    39Наблюдать

    A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    onlyoffice · document server15 апр. 2020 г.

  • CVE-2021-25829
    32Наблюдать

    An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %

    onlyoffice · document server1 мар. 2021 г.

  • CVE-2021-43449
    32Наблюдать

    ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF).

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    onlyoffice · server23 янв. 2023 г.

  • CVE-2023-30188
    31Наблюдать

    Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via c

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    onlyoffice · document server14 авг. 2023 г.

  • CVE-2022-48422
    31Наблюдать

    ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the cur

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    onlyoffice · document server18 мар. 2023 г.

  • CVE-2021-43447
    30Наблюдать

    ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    onlyoffice · server23 янв. 2023 г.

  • CVE-2021-43444
    30Наблюдать

    ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    onlyoffice · server23 янв. 2023 г.

  • CVE-2023-46988
    26Наблюдать

    Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating th

    СредняяCVSS 6,7Proof of conceptEPSS 1 %

    onlyoffice · document server1 апр. 2025 г.

  • CVE-2022-24229
    25Наблюдать

    A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    onlyoffice · document server8 апр. 2022 г.

  • CVE-2021-43446
    24Наблюдать

    ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS).

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    onlyoffice · server23 янв. 2023 г.