Filters

Apache OFBizApache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE

First published (updated )

Apache OFBizApache OFBiz: Confused controller-view authorization logic (forced browsing)

First published (updated )

Apache OFBizApache OFBiz Incorrect Authorization Vulnerability

First published (updated )

Apache OFBizApache OFBiz Path Traversal Vulnerability

First published (updated )

Apache OFBizApache OFBiz: Path traversal or file inclusion

EPSS
0.05%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

BleepingComputerApache OFBiz RCE flaw exploited to find vulnerable Confluence servers

First published (updated )

Apache OFBizApache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability

First published (updated )

Apache OFBizApache OFBiz: Arbitrary file properties reading and SSRF attack

7.5
First published (updated )

Apache OFBizPre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present

First published (updated )

Apache OFBizApache OFBiz: Execution of Solr plugin queries without authentication

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache OFBizApache OFBiz: Arbitrary file reading vulnerability

7.5
First published (updated )

Apache OFBizRegular Expression Denial of Service (ReDoS) vulnerability in Apache OFBiz

7.5
First published (updated )

Apache OFBizJava Deserialization via RMI Connection from the Solr plugin of Apache OFBiz

First published (updated )

Apache OFBizServer-Side Template Injection affecting the ecommerce plugin of Apache OFBiz

7.5
First published (updated )

Apache OFBizUnauth Path Traversal with file corruption affecting the Birt plugin of Apache OFBiz

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache OFBizUnauth Stored XSS vulnerability in the Birt plugin of Apache OFBiz

First published (updated )

Apache OFBizGeneration of Error Message Containing Sensitive Information in Apache OFBiz

7.5
First published (updated )

Apache OFBizArbitrary file upload vulnerability in OFBiz

First published (updated )

Apache OFBizUnsafe deserialization in Apache OFBiz

First published (updated )

Apache OFBizRCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache OFBizRCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI

First published (updated )

Apache OFBizXSS

First published (updated )

Apache OFBizIDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 1…

First published (updated )

Apache OFBizCSRF

8.8
First published (updated )

Apache OFBizCSRF

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache OFBizXSS

First published (updated )

Apache OFBizan unauthenticated user could get access to information of some backend screens by invoking setSessi…

First published (updated )

Apache OFBizXEE

7.5
First published (updated )

Apache OFBizAn RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when …

First published (updated )

Apache OFBizXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache OFBizThe java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is expose…

First published (updated )

Apache OFBizThe Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for …

First published (updated )

Apache OFBizInfoleak

7.5
First published (updated )

Apache OFBizXSS, Code Injection

First published (updated )

Apache OFBizApache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecifi…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache OFBizInput Validation

8.8
First published (updated )

Apache OFBizXSS

First published (updated )

Apache OFBizXSS

First published (updated )

Apache OFBizInput Validation

First published (updated )

Apache OFBizXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache OFBizXSS

First published (updated )

Apache OFBizXSS

3.5
First published (updated )

Apache OFBizInput Validation

First published (updated )

Apache OFBizXSS

First published (updated )

Apache OFBizUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.0…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Apache OFBizXSS

First published (updated )

Apache OpentapsXSS

First published (updated )

Apache OFBizThe forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) …

7.5
First published (updated )

Apache OFBizXSS

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203