ONLYOFFICE kayıtları
onlyoffice üreticisine ait 31 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-787 Out-of-bounds Write4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-20 Improper Input Validation3
- CWE-287 Improper Authentication2
- CWE-427 Uncontrolled Search Path Element1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
31 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2021-25833İstismar yok | A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21.onlyoffice · document server · CWE-22 | Kritik9,8 | — | %43,5 | 1 Mar 2021 |
43Planlayın | CVE-2021-25832İstismar yok | A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0.onlyoffice · document server · CWE-787 | Kritik9,8 | — | %12,6 | 1 Mar 2021 |
43Planlayın | CVE-2021-25830İstismar yok | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13.onlyoffice · document server | Kritik9,8 | — | %11,8 | 1 Mar 2021 |
42Planlayın | CVE-2021-25831İstismar yok | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.onlyoffice · document server | Kritik9,8 | — | %11,5 | 1 Mar 2021 |
41Planlayın | CVE-2021-3199İstismar yok | Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /..onlyoffice · document server · CWE-22 | Kritik9,8 | — | %8,2 | 26 Oca 2021 |
41Planlayın | CVE-2022-29776İstismar yok | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component Desktoonlyoffice · core · CWE-787 | Kritik9,8 | — | %6,9 | 2 Haz 2022 |
41Planlayın | CVE-2022-29777İstismar yok | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component Desktoponlyoffice · core · CWE-787 | Kritik9,8 | — | %6,9 | 2 Haz 2022 |
41Planlayın | CVE-2023-34939İstismar yok | Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProonlyoffice · onlyoffice · CWE-22 | Kritik9,8 | — | %5,0 | 22 Haz 2023 |
40Planlayın | CVE-2020-11536İstismar yok | An issue was discovered in ONLYOFFICE Document Server 5.5.0.onlyoffice · document server · CWE-20 | Kritik9,8 | — | %2,6 | 15 Nis 2020 |
40Planlayın | CVE-2023-30187İstismar yok | An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code onlyoffice · document server · CWE-787 | Kritik9,8 | — | %2,4 | 14 Ağu 2023 |
40Planlayın | CVE-2020-11535İstismar yok | An issue was discovered in ONLYOFFICE Document Server 5.5.0.onlyoffice · document server · CWE-91 | Kritik9,8 | — | %2,3 | 15 Nis 2020 |
40Planlayın | CVE-2021-40864İstismar yok | The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.onlyoffice · google translate | Kritik9,8 | — | %2,3 | 10 Eyl 2021 |
40Planlayın | CVE-2023-30186İstismar yok | A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via craftedonlyoffice · document server · CWE-416 | Kritik9,8 | — | %2,3 | 14 Ağu 2023 |
40Planlayın | CVE-2020-11534İstismar yok | An issue was discovered in ONLYOFFICE Document Server 5.5.0.onlyoffice · document server · CWE-20 | Kritik9,8 | — | %2,2 | 15 Nis 2020 |
40Planlayın | CVE-2021-43445İstismar yok | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.onlyoffice · server · CWE-287 | Kritik9,8 | — | %1,7 | 23 Oca 2023 |
39İzleyin | CVE-2020-11537İstismar yok | A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0.onlyoffice · document server · CWE-89 | Kritik9,8 | — | %1,5 | 15 Nis 2020 |
32İzleyin | CVE-2021-25829İstismar yok | An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.onlyoffice · document server | Yüksek7,5 | — | %7,4 | 1 Mar 2021 |
32İzleyin | CVE-2021-43449İstismar yok | ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF).onlyoffice · server · CWE-918 | Yüksek8,1 | — | %1,2 | 23 Oca 2023 |
31İzleyin | CVE-2023-30188İstismar yok | Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via conlyoffice · document server · CWE-835 | Yüksek7,5 | — | %2,2 | 14 Ağu 2023 |
31İzleyin | CVE-2022-48422İstismar yok | ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the curonlyoffice · document server · CWE-427 | Yüksek7,8 | — | %0,3 | 18 Mar 2023 |
30İzleyin | CVE-2021-43447İstismar yok | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.onlyoffice · server · CWE-306 | Yüksek7,5 | — | %1,3 | 23 Oca 2023 |
30İzleyin | CVE-2021-43444İstismar yok | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.onlyoffice · server · CWE-287 | Yüksek7,5 | — | %1,2 | 23 Oca 2023 |
26İzleyin | CVE-2023-46988Kavram kanıtı | Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating thonlyoffice · document server · CWE-22 | Orta6,7 | — | %0,5 | 1 Nis 2025 |
25İzleyin | CVE-2022-24229İstismar yok | A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTMLonlyoffice · document server · CWE-79 | Orta6,1 | — | %1,9 | 8 Nis 2022 |
24İzleyin | CVE-2021-43446İstismar yok | ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS).onlyoffice · server · CWE-79 | Orta6,1 | — | %0,8 | 23 Oca 2023 |
- CVE-2021-2583352Planlayın
A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21.
KritikCVSS 9,8İstismar yokEPSS %44onlyoffice · document server1 Mar 2021
- CVE-2021-2583243Planlayın
A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0.
KritikCVSS 9,8İstismar yokEPSS %13onlyoffice · document server1 Mar 2021
- CVE-2021-2583043Planlayın
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13.
KritikCVSS 9,8İstismar yokEPSS %12onlyoffice · document server1 Mar 2021
- CVE-2021-2583142Planlayın
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.
KritikCVSS 9,8İstismar yokEPSS %12onlyoffice · document server1 Mar 2021
- CVE-2021-319941Planlayın
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /..
KritikCVSS 9,8İstismar yokEPSS %8onlyoffice · document server26 Oca 2021
- CVE-2022-2977641Planlayın
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component Deskto
KritikCVSS 9,8İstismar yokEPSS %7onlyoffice · core2 Haz 2022
- CVE-2022-2977741Planlayın
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component Desktop
KritikCVSS 9,8İstismar yokEPSS %7onlyoffice · core2 Haz 2022
- CVE-2023-3493941Planlayın
Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadPro
KritikCVSS 9,8İstismar yokEPSS %5onlyoffice · onlyoffice22 Haz 2023
- CVE-2020-1153640Planlayın
An issue was discovered in ONLYOFFICE Document Server 5.5.0.
KritikCVSS 9,8İstismar yokEPSS %3onlyoffice · document server15 Nis 2020
- CVE-2023-3018740Planlayın
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code
KritikCVSS 9,8İstismar yokEPSS %2onlyoffice · document server14 Ağu 2023
- CVE-2020-1153540Planlayın
An issue was discovered in ONLYOFFICE Document Server 5.5.0.
KritikCVSS 9,8İstismar yokEPSS %2onlyoffice · document server15 Nis 2020
- CVE-2021-4086440Planlayın
The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.
KritikCVSS 9,8İstismar yokEPSS %2onlyoffice · google translate10 Eyl 2021
- CVE-2023-3018640Planlayın
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted
KritikCVSS 9,8İstismar yokEPSS %2onlyoffice · document server14 Ağu 2023
- CVE-2020-1153440Planlayın
An issue was discovered in ONLYOFFICE Document Server 5.5.0.
KritikCVSS 9,8İstismar yokEPSS %2onlyoffice · document server15 Nis 2020
- CVE-2021-4344540Planlayın
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.
KritikCVSS 9,8İstismar yokEPSS %2onlyoffice · server23 Oca 2023
- CVE-2020-1153739İzleyin
A SQL Injection issue was discovered in ONLYOFFICE Document Server 5.5.0.
KritikCVSS 9,8İstismar yokEPSS %1onlyoffice · document server15 Nis 2020
- CVE-2021-2582932İzleyin
An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3.
YüksekCVSS 7,5İstismar yokEPSS %7onlyoffice · document server1 Mar 2021
- CVE-2021-4344932İzleyin
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF).
YüksekCVSS 8,1İstismar yokEPSS %1onlyoffice · server23 Oca 2023
- CVE-2023-3018831İzleyin
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via c
YüksekCVSS 7,5İstismar yokEPSS %2onlyoffice · document server14 Ağu 2023
- CVE-2022-4842231İzleyin
ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the cur
YüksekCVSS 7,8İstismar yokEPSS %0onlyoffice · document server18 Mar 2023
- CVE-2021-4344730İzleyin
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.
YüksekCVSS 7,5İstismar yokEPSS %1onlyoffice · server23 Oca 2023
- CVE-2021-4344430İzleyin
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control.
YüksekCVSS 7,5İstismar yokEPSS %1onlyoffice · server23 Oca 2023
- CVE-2023-4698826İzleyin
Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating th
OrtaCVSS 6,7Kavram kanıtıEPSS %1onlyoffice · document server1 Nis 2025
- CVE-2022-2422925İzleyin
A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML
OrtaCVSS 6,1İstismar yokEPSS %2onlyoffice · document server8 Nis 2022
- CVE-2021-4344624İzleyin
ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS).
OrtaCVSS 6,1İstismar yokEPSS %1onlyoffice · server23 Oca 2023