CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2021-43269 HIGH

In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading…

CVSS 8.8 EPSS 1.34% Jan 20, 2022
CVE-2020-12736 HIGH

Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO…

CVSS 7.2 EPSS 2.03% Jul 7, 2020
CVE-2019-16861 HIGH

Code42 server through 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local server could create or…

CVSS 7.3 EPSS 0.38% Nov 19, 2019
CVE-2019-16860 HIGH

Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local machine could crea…

CVSS 7.3 EPSS 0.37% Nov 19, 2019
CVE-2019-15131 CRITICAL

In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploaded to Cod…

CVSS 9.8 EPSS 1.88% Sep 17, 2019
CVE-2019-11551 MEDIUM

In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code4…

CVSS 5.5 EPSS 0.25% Aug 21, 2019
CVE-2019-11553 HIGH

In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organization can impersonate…

CVSS 8.8 EPSS 0.95% Jul 19, 2019
CVE-2019-11552 HIGH

Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-…

CVSS 7.0 EPSS 0.55% Jul 19, 2019
CVE-2018-20131 HIGH

The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashplan/log directory.…

CVSS 7.8 EPSS 0.30% Jan 3, 2019
CVE-2017-9830 CRITICAL

Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it creates an R…

CVSS 9.8 EPSS 6.48% Jun 27, 2017

Showing 1 to 10 CVEs · page 1