Seafile kayıtları
seafile üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %16,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-326 Inadequate Encryption Strength1
- CWE-330 Use of Insufficiently Random Values1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2026-30587İstismar yok | Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro,seafile · seafile server · CWE-79 | Yüksek8,7 | — | %0,5 | 25 Mar 2026 |
31İzleyin | CVE-2020-16143İstismar yok | The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.seafile · seafile-client · CWE-427 | Yüksek7,8 | — | %0,4 | 29 Tem 2020 |
31İzleyin | CVE-2014-5443İstismar yok | Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet hseafile · seafile server · CWE-264 | Yüksek7,8 | — | %0,4 | 19 Mar 2018 |
30İzleyin | CVE-2019-8919İstismar yok | The seadroid (aka Seafile Android Client) application through 2.2.13 for Android always uses the same Initialization Vector (IV) with Cipherseafile · seadroid · CWE-330 | Yüksek7,5 | — | %1,4 | 18 Şub 2019 |
30İzleyin | CVE-2013-7469İstismar yok | Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, makingseafile · seafile · CWE-326 | Yüksek7,5 | — | %1,1 | 20 Şub 2019 |
24İzleyin | CVE-2023-28874İstismar yok | The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.seafile · seafile · CWE-601 | Orta6,1 | — | %0,5 | 9 Ara 2023 |
24İzleyin | CVE-2025-65516İstismar yok | A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12.seafile · seafile server · CWE-79 | Orta6,1 | — | %0,2 | 4 Ara 2025 |
23İzleyin | CVE-2021-43820İstismar yok | Permissions check bypass in Seafileseafile · seafile server · CWE-639 | Orta5,9 | — | %1,0 | 14 Ara 2021 |
21İzleyin | CVE-2021-30146Kavram kanıtı | Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."seafile · seafile · CWE-79 | Orta5,4 | — | %0,9 | 6 Nis 2021 |
21İzleyin | CVE-2023-28873İstismar yok | An XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown editor.seafile · seafile · CWE-79 | Orta5,4 | — | %0,4 | 9 Ara 2023 |
20İzleyin | CVE-2025-41079İstismar yok | Multiple vulnerabilities in Seafileseafile · seafile · CWE-79 | Orta5,1 | — | %0,2 | 4 Ara 2025 |
20İzleyin | CVE-2025-41080İstismar yok | Multiple vulnerabilities in Seafileseafile · seafile · CWE-79 | Orta5,1 | — | %0,2 | 4 Ara 2025 |
- CVE-2026-3058734İzleyin
Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro,
YüksekCVSS 8,7İstismar yokEPSS %0seafile · seafile server25 Mar 2026
- CVE-2020-1614331İzleyin
The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.
YüksekCVSS 7,8İstismar yokEPSS %0seafile · seafile-client29 Tem 2020
- CVE-2014-544331İzleyin
Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet h
YüksekCVSS 7,8İstismar yokEPSS %0seafile · seafile server19 Mar 2018
- CVE-2019-891930İzleyin
The seadroid (aka Seafile Android Client) application through 2.2.13 for Android always uses the same Initialization Vector (IV) with Cipher
YüksekCVSS 7,5İstismar yokEPSS %1seafile · seadroid18 Şub 2019
- CVE-2013-746930İzleyin
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making
YüksekCVSS 7,5İstismar yokEPSS %1seafile · seafile20 Şub 2019
- CVE-2023-2887424İzleyin
The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.
OrtaCVSS 6,1İstismar yokEPSS %0seafile · seafile9 Ara 2023
- CVE-2025-6551624İzleyin
A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12.
OrtaCVSS 6,1İstismar yokEPSS %0seafile · seafile server4 Ara 2025
- CVE-2021-4382023İzleyin
Permissions check bypass in Seafile
OrtaCVSS 5,9İstismar yokEPSS %1seafile · seafile server14 Ara 2021
- CVE-2021-3014621İzleyin
Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."
OrtaCVSS 5,4Kavram kanıtıEPSS %1seafile · seafile6 Nis 2021
- CVE-2023-2887321İzleyin
An XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown editor.
OrtaCVSS 5,4İstismar yokEPSS %0seafile · seafile9 Ara 2023
- CVE-2025-4107920İzleyin
Multiple vulnerabilities in Seafile
OrtaCVSS 5,1İstismar yokEPSS %0seafile · seafile4 Ara 2025
- CVE-2025-4108020İzleyin
Multiple vulnerabilities in Seafile
OrtaCVSS 5,1İstismar yokEPSS %0seafile · seafile4 Ara 2025