CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
LogicalDOC Enterprise 7.7.4 Multiple Post-Authentication Directory Traversal Vulnerabilities
LogicalDOC Community Edition Admin Login login.jsp excessive authentication
LogicalDOC Community Edition API Key creation UI cross site scripting
LogicalDOC Community Edition Add Contact frontend.jsp cross site scripting
Blind SQL Injection in Logout
Reflected Cross-Site Scripting (XSS)
Arbitrary File Read via Document API
Remote Code Execution (RCE) via Arbitrary File Write In Document API
Remote Code Execution (RCE) via Automation Scripting
Blind SQLi in Saved Search
Blind SQLi in Document History
Blind SQLi in Login
LogicalDOC Document Version Comment Stored XSS
LogicalDOC Document File Name Stored XSS
LogicalDOC Chat Stored XSS
LogicalDOC Messaging Stored XSS
A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an attacker c…
LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.
LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by mod…
LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. LogicalDoc prov…
LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and the creation of directories, in the cl…
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.
LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
Showing 1 to 24 CVEs · page 1