filecloud records
7 published records for vendor filecloud.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 14.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-284 Improper Access Control1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2022-25241Proof of concept | In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).filecloud · filecloud · CWE-352 | High8.8 | — | 3.3% | Feb 15, 2022 |
35Monitor | CVE-2016-6578No exploit | CodeLathe FileCloud, version 13.0.0.32841 and earlier, is vulnerable to cross-site request forgery (CSRF)filecloud · filecloud · CWE-352 | High8.8 | — | 0.9% | Jul 13, 2018 |
35Monitor | CVE-2022-25242No exploit | In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).filecloud · filecloud · CWE-352 | High8.8 | — | 0.4% | Feb 15, 2022 |
29Monitor | CVE-2022-39833No exploit | FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported APIfilecloud · filecloud · CWE-94 | High7.2 | — | 2.8% | Nov 23, 2022 |
26Monitor | CVE-2022-1958No exploit | FileCloud NTFS access controlfilecloud · filecloud · CWE-284 | Medium6.5 | — | 0.7% | Jun 15, 2022 |
21Monitor | CVE-2020-26524No exploit | CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.filecloud · filecloud | Medium5.3 | — | 1.4% | Oct 2, 2020 |
21Monitor | CVE-2022-24633No exploit | All versions of FileCloud prior to 21.3 are vulnerable to user enumeration.filecloud · filecloud · CWE-200 | Medium5.3 | — | 0.8% | Feb 24, 2022 |
- CVE-2022-2524136Monitor
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
HighCVSS 8.8Proof of conceptEPSS 3%filecloud · filecloudFeb 15, 2022
- CVE-2016-657835Monitor
CodeLathe FileCloud, version 13.0.0.32841 and earlier, is vulnerable to cross-site request forgery (CSRF)
HighCVSS 8.8No exploitEPSS 1%filecloud · filecloudJul 13, 2018
- CVE-2022-2524235Monitor
In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).
HighCVSS 8.8No exploitEPSS 0%filecloud · filecloudFeb 15, 2022
- CVE-2022-3983329Monitor
FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API
HighCVSS 7.2No exploitEPSS 3%filecloud · filecloudNov 23, 2022
- CVE-2022-195826Monitor
FileCloud NTFS access control
MediumCVSS 6.5No exploitEPSS 1%filecloud · filecloudJun 15, 2022
- CVE-2020-2652421Monitor
CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
MediumCVSS 5.3No exploitEPSS 1%filecloud · filecloudOct 2, 2020
- CVE-2022-2463321Monitor
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration.
MediumCVSS 5.3No exploitEPSS 1%filecloud · filecloudFeb 24, 2022