İçeriğe atla
Noroxi

pydio kayıtları

pydio üreticisine ait 36 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
4
Düzeltme kaydı olan
%5,6
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

36 kayıt
  • CVE-2013-4267
    40Planlayın

    Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to

    KritikCVSS 9,8İstismar yokEPSS %4

    pydio · pydio11 Şub 2020

  • CVE-2015-3431
    40Planlayın

    Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Comman

    KritikCVSS 9,8İstismar yokEPSS %4

    pydio · pydio19 Eyl 2017

  • CVE-2018-20718
    40Planlayın

    In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    pydio · pydio15 Oca 2019

  • CVE-2019-9642
    40Planlayın

    An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2.

    KritikCVSS 9,8İstismar yokEPSS %2

    pydio · pydio5 Haz 2019

  • CVE-2023-32749
    39İzleyin

    Pydio Cells allows users by default to create so-called external users in order to share files with them.

    YüksekCVSS 8,8Kavram kanıtıEPSS %14

    pydio · cells8 Haz 2023

  • CVE-2019-20452
    36İzleyin

    A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4.

    YüksekCVSS 8,8İstismar yokEPSS %2

    pydio · pydio17 Mar 2020

  • CVE-2019-20453
    36İzleyin

    A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4.

    YüksekCVSS 8,8İstismar yokEPSS %2

    pydio · pydio17 Mar 2020

  • CVE-2019-12901
    35İzleyin

    Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete file

    YüksekCVSS 8,8İstismar yokEPSS %2

    pydio · cells19 Haz 2019

  • CVE-2013-6227
    32İzleyin

    Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5

    YüksekCVSS 7,5Kavram kanıtıEPSS %8

    ajaxplorer · ajaxplorer27 Ara 2014

  • CVE-2020-12851
    32İzleyin

    Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositori

    YüksekCVSS 8,1İstismar yokEPSS %1

    pydio · cells4 Haz 2020

  • CVE-2018-14772
    30İzleyin

    Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web

    YüksekCVSS 7,2Kavram kanıtıEPSS %6

    pydio · pydio16 Eki 2018

  • CVE-2019-15033
    30İzleyin

    Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download.

    YüksekCVSS 7,7İstismar yokEPSS %1

    pydio · pydio19 Eyl 2019

  • CVE-2019-10048
    29İzleyin

    The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation and sanitization of u

    YüksekCVSS 7,2İstismar yokEPSS %3

    pydio · pydio31 May 2019

  • CVE-2020-12847
    29İzleyin

    Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator ro

    YüksekCVSS 7,2İstismar yokEPSS %2

    pydio · cells4 Haz 2020

  • CVE-2019-10049
    29İzleyin

    It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into op

    YüksekCVSS 7,3İstismar yokEPSS %1

    pydio · pydio31 May 2019

  • CVE-2020-12852
    28İzleyin

    The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the

    OrtaCVSS 6,8İstismar yokEPSS %2

    pydio · cells4 Haz 2020

  • CVE-2020-12850
    28İzleyin

    The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4.

    YüksekCVSS 7,0İstismar yokEPSS %0

    pydio · cells10 Haz 2020

  • CVE-2023-32750
    27İzleyin

    Pydio Cells through 4.1.2 allows SSRF.

    OrtaCVSS 6,5Kavram kanıtıEPSS %4

    pydio · cells8 Haz 2023

  • Pydio version 8.2.1 and prior contains an Unvalidated user input leading to Remote Code Execution (RCE) vulnerability in plugins/action.anti

    OrtaCVSS 6,6İstismar yokEPSS %3

    pydio · pydio23 Tem 2018

  • CVE-2021-41324
    27İzleyin

    Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal file

    OrtaCVSS 6,5İstismar yokEPSS %2

    pydio · cells30 Eyl 2021

  • CVE-2021-41323
    27İzleyin

    Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells fil

    OrtaCVSS 6,5İstismar yokEPSS %2

    pydio · cells30 Eyl 2021

  • CVE-2021-41325
    26İzleyin

    Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile paramete

    OrtaCVSS 6,5İstismar yokEPSS %1

    pydio · cells30 Eyl 2021

  • CVE-2019-12902
    26İzleyin

    Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion.

    OrtaCVSS 6,5İstismar yokEPSS %1

    pydio · cells19 Haz 2019

  • CVE-2019-10045
    26İzleyin

    The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scr

    OrtaCVSS 6,5İstismar yokEPSS %1

    pydio · pydio31 May 2019

  • Pydio version 8.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in ./core/vendor/meenie/javascript-packer/example-inline

    OrtaCVSS 6,1İstismar yokEPSS %1

    pydio · pydio23 Tem 2018