Lucene search

K

Community Server Security Vulnerabilities

cve
cve

CVE-2024-2965

A Denial-of-Service (DoS) vulnerability exists in the SitemapLoader class of the langchain-community package, affecting all versions. The parse_sitemap method, responsible for parsing sitemaps and extracting URLs, lacks a mechanism to prevent infinite recursion when a sitemap URL refers to the...

4.2CVSS

4.3AI Score

0.0004EPSS

2024-06-06 07:15 PM
27
cve
cve

CVE-2024-23793

The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or customer users to upload potentially harmful files to directories accessible by the web server, potentially leading to the execution of local code like Perl....

6.3CVSS

7.2AI Score

0.0004EPSS

2024-06-06 07:15 PM
21
cve
cve

CVE-2024-3462

Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users. All versions up to 2.9.0 (tested) and possibly newer ones are believed to be...

6.7AI Score

0.0004EPSS

2024-05-14 03:41 PM
21
cve
cve

CVE-2024-2796

A server-side request forgery (SSRF) was discovered in the Akana Community Manager Developer Portal in versions prior to and including 2022.1.3. Reported by Jakob...

9.3CVSS

9.4AI Score

0.0004EPSS

2024-04-18 03:15 PM
27
cve
cve

CVE-2023-27630

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through...

5.3CVSS

6.7AI Score

0.0004EPSS

2024-03-26 08:15 PM
30
cve
cve

CVE-2023-46850

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote...

9.8CVSS

9.6AI Score

0.005EPSS

2023-11-11 01:15 AM
55
cve
cve

CVE-2023-46849

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of...

7.5CVSS

8AI Score

0.001EPSS

2023-11-11 01:15 AM
34
cve
cve

CVE-2023-32608

Directory traversal vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticated attacker to alter an arbitrary file on the...

6.5CVSS

6.2AI Score

0.001EPSS

2023-06-30 03:15 AM
22
cve
cve

CVE-2021-44476

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read local files on the server, including sensitive configuration...

6.8CVSS

6.4AI Score

0.001EPSS

2023-04-25 07:15 PM
17
cve
cve

CVE-2021-23166

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the...

8.7CVSS

8.1AI Score

0.001EPSS

2023-04-25 07:15 PM
17
cve
cve

CVE-2023-0265

Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by...

8.8CVSS

8.8AI Score

0.001EPSS

2023-04-04 10:15 PM
16
cve
cve

CVE-2022-41562

The HTML escaping component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS...

8.4CVSS

7.9AI Score

0.001EPSS

2022-12-13 07:15 PM
28
cve
cve

CVE-2022-41561

The JNDI Data Sources component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS...

9.1CVSS

7.3AI Score

0.002EPSS

2022-12-13 07:15 PM
35
cve
cve

CVE-2022-46157

Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote authenticated users to execute arbitrary PHP code on the server by uploading a crafted image. Akeneo PIM Community Edition after the versions...

8.8CVSS

8.7AI Score

0.004EPSS

2022-12-09 09:15 PM
252
cve
cve

CVE-2014-9302

Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition 5.0.a and earlier allows remote attackers to trigger outbound requests via a crafted URI in the url...

6.8AI Score

0.008EPSS

2022-10-03 04:20 PM
18
cve
cve

CVE-2021-40604

A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by an unauthenticated...

9.1CVSS

8.8AI Score

0.003EPSS

2022-06-13 06:15 PM
44
2
cve
cve

CVE-2022-22778

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A successful attack...

8.8CVSS

8.8AI Score

0.001EPSS

2022-05-18 05:15 PM
41
6
cve
cve

CVE-2022-22776

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using.....

8CVSS

5.4AI Score

0.001EPSS

2022-05-18 05:15 PM
108
6
cve
cve

CVE-2022-22777

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow an unauthenticated attacker with network access to execute scripts targeting the affected system or the...

6.1CVSS

6.3AI Score

0.001EPSS

2022-05-18 05:15 PM
48
5
cve
cve

CVE-2022-22773

The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports...

7.7CVSS

5.5AI Score

0.001EPSS

2022-05-17 06:15 PM
632
5
cve
cve

CVE-2021-43055

The eFTL Server component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains an easily exploitable vulnerability that allows clients to inherit the permissions of the client that initially connected on the affected.....

8.8CVSS

8.7AI Score

0.001EPSS

2022-01-11 07:15 PM
25
cve
cve

CVE-2021-43053

The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a difficult to exploit vulnerability that allows an unauthenticated attacker with network access to obtain the cluster secret of another...

8.5CVSS

7.4AI Score

0.002EPSS

2022-01-11 07:15 PM
26
cve
cve

CVE-2021-43054

The eFTL Server component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains an easily exploitable vulnerability that allows a low privileged attacker with network access to generate API tokens that can access any...

8.8CVSS

8.5AI Score

0.001EPSS

2022-01-11 07:15 PM
24
cve
cve

CVE-2021-43052

The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret used in the default realm server of the...

9.3CVSS

7.7AI Score

0.001EPSS

2022-01-11 07:15 PM
23
cve
cve

CVE-2021-35494

The Rest API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS...

5.7CVSS

4.8AI Score

0.001EPSS

2021-10-12 06:15 PM
26
cve
cve

CVE-2021-35495

The Scheduler Connection component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for....

9CVSS

8.4AI Score

0.001EPSS

2021-10-12 06:15 PM
26
cve
cve

CVE-2021-35496

The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS....

7.5CVSS

7.2AI Score

0.001EPSS

2021-10-12 06:15 PM
33
cve
cve

CVE-2021-35497

The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, TIBCO ActiveSpaces - Enterprise Edition, TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO...

7.5CVSS

7.5AI Score

0.001EPSS

2021-10-05 06:15 PM
33
cve
cve

CVE-2021-28822

The Enterprise Message Service Server (tibemsd), Enterprise Message Service Central Administration (tibemsca), Enterprise Message Service JSON configuration generator (tibemsconf2json), and Enterprise Message Service C API components of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO....

8.8CVSS

7.5AI Score

0.0004EPSS

2021-03-23 09:15 PM
34
2
cve
cve

CVE-2021-28820

The FTL Server (tibftlserver), FTL C API, FTL Golang API, FTL Java API, and FTL .Net API components of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contain a vulnerability that theoretically allows a low privileged attacker.....

8.8CVSS

7.5AI Score

0.0004EPSS

2021-03-23 09:15 PM
29
cve
cve

CVE-2012-2148

An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security...

3.3CVSS

4.3AI Score

0.0005EPSS

2019-12-06 06:15 PM
101
cve
cve

CVE-2018-18816

The repository component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS contains a persistent cross...

8CVSS

5.4AI Score

0.001EPSS

2019-03-07 10:29 PM
22
cve
cve

CVE-2018-18815

The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that....

10CVSS

9.4AI Score

0.016EPSS

2019-03-07 10:29 PM
29
cve
cve

CVE-2018-18809

The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for...

6.5CVSS

6.5AI Score

0.503EPSS

2019-03-07 10:29 PM
465
In Wild
cve
cve

CVE-2018-18808

The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a...

8.8CVSS

7.7AI Score

0.003EPSS

2019-03-07 10:29 PM
29
cve
cve

CVE-2019-3911

Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror parameter in the /__r2/query...

6.1CVSS

6AI Score

0.002EPSS

2019-01-30 08:29 PM
30
cve
cve

CVE-2019-3912

An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web...

6.1CVSS

6.3AI Score

0.002EPSS

2019-01-30 08:29 PM
18
cve
cve

CVE-2019-3913

Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drive on the system leading to denial of...

4.9CVSS

5.1AI Score

0.005EPSS

2019-01-30 08:29 PM
24
cve
cve

CVE-2018-12412

The realm server (tibrealmserver) component of TIBCO Software Inc. TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO....

8.8CVSS

8.7AI Score

0.003EPSS

2018-11-06 11:29 PM
21
cve
cve

CVE-2018-12415

The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability which may allow an attacker to perform cross-site...

8.8CVSS

8.7AI Score

0.003EPSS

2018-11-06 11:29 PM
19
cve
cve

CVE-2018-12413

The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition contains a vulnerability which may allow an...

8.8CVSS

8.7AI Score

0.003EPSS

2018-11-06 11:29 PM
29
cve
cve

CVE-2018-1153

Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view...

7.4CVSS

7.3AI Score

0.001EPSS

2018-06-18 02:29 PM
26
cve
cve

CVE-2018-5429

A vulnerability in the report scripting component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports...

8.8CVSS

8.7AI Score

0.001EPSS

2018-04-17 06:29 PM
28
cve
cve

CVE-2018-5431

The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a...

6.3CVSS

5.2AI Score

0.001EPSS

2018-04-17 06:29 PM
22
cve
cve

CVE-2018-5430

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which...

8.8CVSS

8.4AI Score

0.059EPSS

2018-04-17 06:29 PM
450
In Wild
cve
cve

CVE-2017-5530

The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0,...

8.1CVSS

8.1AI Score

0.001EPSS

2017-12-13 02:29 AM
24
cve
cve

CVE-2017-5533

A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which....

9.8CVSS

9.2AI Score

0.004EPSS

2017-11-17 12:00 AM
28
cve
cve

CVE-2017-5532

A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy,....

5.4CVSS

5.1AI Score

0.001EPSS

2017-11-17 12:00 AM
32
cve
cve

CVE-2017-5529

JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versions 6.4.0 and below), TIBCO JasperReports...

6.5CVSS

7AI Score

0.001EPSS

2017-06-29 02:29 PM
33
cve
cve

CVE-2017-5528

Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of sensitive information. Affects TIBCO...

8.8CVSS

8.5AI Score

0.001EPSS

2017-06-29 02:29 PM
47
2
Total number of security vulnerabilities66