CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2024-34891 MEDIUM

Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account passwords vi…

CVSS 6.8 EPSS 0.29% Nov 4, 2024
CVE-2024-34887 MEDIUM

Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators ac…

CVSS 6.8 EPSS 0.34% Nov 4, 2024
CVE-2024-34885 MEDIUM

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via…

CVSS 6.8 EPSS 0.43% Nov 4, 2024
CVE-2024-34883 MEDIUM

Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts password…

CVSS 6.8 EPSS 0.38% Nov 4, 2024
CVE-2024-34882 MEDIUM

Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an…

CVSS 6.8 EPSS 0.34% Nov 4, 2024
CVE-2017-20122 MEDIUM

Bitrix Site Manager Contact Form cross site scripting

CVSS 5.4 EPSS 0.54% Jun 30, 2022
CVE-2020-13758 MEDIUM

modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by placing %00 before…

CVSS 6.1 EPSS 0.86% Jun 1, 2020
CVE-2015-8356 HIGH

Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated users to execute arbitrary SQL commands…

CVSS 8.0 EPSS 2.73% Apr 14, 2017
CVE-2015-8358 HIGH

Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrary local f…

CVSS 9.0 EPSS 6.63% Dec 16, 2015
CVE-2015-8357 MEDIUM

Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and consequen…

CVSS 6.5 EPSS 8.36% Dec 16, 2015
CVE-2013-6788 HIGH

The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote atta…

CVSS 7.5 EPSS 1.63% May 30, 2014
CVE-2006-2479 MEDIUM

The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers to obtain sensitive…

CVSS 5.0 EPSS 1.91% May 19, 2006
CVE-2006-2478 MEDIUM

Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request. NOTE: this issue has…

CVSS 5.0 EPSS 1.64% May 19, 2006
CVE-2006-2477 MEDIUM

Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrary web script or HT…

CVSS 4.9 EPSS 1.15% May 19, 2006
CVE-2006-2476 MEDIUM

Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive in…

CVSS 5.0 EPSS 2.22% May 19, 2006
CVE-2005-1996 MEDIUM

PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMEN…

CVSS 5.0 EPSS 1.54% Jun 20, 2005
CVE-2005-1995 MEDIUM

Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which rev…

CVSS 5.0 EPSS 1.39% Jun 20, 2005

Showing 1 to 17 CVEs · page 1