İçeriğe atla
Noroxi

ONLYOFFICE kayıtları

onlyoffice üreticisine ait 31 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
9
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

31 kayıt
  • CVE-2021-25833
    52Planlayın

    A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21.

    KritikCVSS 9,8İstismar yokEPSS %44

    onlyoffice · document server1 Mar 2021

  • CVE-2021-25832
    43Planlayın

    A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0.

    KritikCVSS 9,8İstismar yokEPSS %13

    onlyoffice · document server1 Mar 2021

  • CVE-2021-25830
    43Planlayın

    A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13.

    KritikCVSS 9,8İstismar yokEPSS %12

    onlyoffice · document server1 Mar 2021

  • CVE-2021-25831
    42Planlayın

    A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.

    KritikCVSS 9,8İstismar yokEPSS %12

    onlyoffice · document server1 Mar 2021

  • CVE-2021-3199
    41Planlayın

    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /..

    KritikCVSS 9,8İstismar yokEPSS %8

    onlyoffice · document server26 Oca 2021

  • CVE-2022-29776
    41Planlayın

    Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component Deskto

    KritikCVSS 9,8İstismar yokEPSS %7

    onlyoffice · core2 Haz 2022

  • CVE-2022-29777
    41Planlayın

    Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component Desktop

    KritikCVSS 9,8İstismar yokEPSS %7

    onlyoffice · core2 Haz 2022

  • CVE-2023-34939
    41Planlayın

    Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadPro

    KritikCVSS 9,8İstismar yokEPSS %5

    onlyoffice · onlyoffice22 Haz 2023

  • CVE-2020-11536
    40Planlayın

    An issue was discovered in ONLYOFFICE Document Server 5.5.0.

    KritikCVSS 9,8İstismar yokEPSS %3

    onlyoffice · document server15 Nis 2020

  • CVE-2023-30187
    40Planlayın

    An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code

    KritikCVSS 9,8İstismar yokEPSS %2

    onlyoffice · document server14 Ağu 2023

  • CVE-2020-11535
    40Planlayın

    An issue was discovered in ONLYOFFICE Document Server 5.5.0.

    KritikCVSS 9,8İstismar yokEPSS %2

    onlyoffice · document server15 Nis 2020

  • CVE-2021-40864
    40Planlayın

    The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.

    KritikCVSS 9,8İstismar yokEPSS %2

    onlyoffice · google translate10 Eyl 2021

  • CVE-2023-30186
    40Planlayın

    A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted

    KritikCVSS 9,8İstismar yokEPSS %2

    onlyoffice · document server14 Ağu 2023

  • CVE-2020-11534
    40Planlayın

    An issue was discovered in ONLYOFFICE Document Server 5.5.0.

    KritikCVSS 9,8İstismar yokEPSS %2

    onlyoffice · document server15 Nis 2020

  • CVE-2021-43445
    40Planlayın

    ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.

    KritikCVSS 9,8İstismar yokEPSS %2

    onlyoffice · server23 Oca 2023

  • CVE-2020-11537
    39İzleyin

    A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0.

    KritikCVSS 9,8İstismar yokEPSS %1

    onlyoffice · document server15 Nis 2020

  • CVE-2021-25829
    32İzleyin

    An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.

    YüksekCVSS 7,5İstismar yokEPSS %7

    onlyoffice · document server1 Mar 2021

  • CVE-2021-43449
    32İzleyin

    ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF).

    YüksekCVSS 8,1İstismar yokEPSS %1

    onlyoffice · server23 Oca 2023

  • CVE-2023-30188
    31İzleyin

    Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via c

    YüksekCVSS 7,5İstismar yokEPSS %2

    onlyoffice · document server14 Ağu 2023

  • CVE-2022-48422
    31İzleyin

    ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the cur

    YüksekCVSS 7,8İstismar yokEPSS %0

    onlyoffice · document server18 Mar 2023

  • CVE-2021-43447
    30İzleyin

    ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.

    YüksekCVSS 7,5İstismar yokEPSS %1

    onlyoffice · server23 Oca 2023

  • CVE-2021-43444
    30İzleyin

    ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.

    YüksekCVSS 7,5İstismar yokEPSS %1

    onlyoffice · server23 Oca 2023

  • CVE-2023-46988
    26İzleyin

    Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating th

    OrtaCVSS 6,7Kavram kanıtıEPSS %1

    onlyoffice · document server1 Nis 2025

  • CVE-2022-24229
    25İzleyin

    A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML

    OrtaCVSS 6,1İstismar yokEPSS %2

    onlyoffice · document server8 Nis 2022

  • CVE-2021-43446
    24İzleyin

    ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS).

    OrtaCVSS 6,1İstismar yokEPSS %1

    onlyoffice · server23 Oca 2023