Vulnerabilities (CVE)

Filtered by CWE-184
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-6189 1 Alinto 1 Sogo 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.
CVE-2015-5946 1 Sugarcrm 1 Sugarcrm 2024-11-21 4.6 MEDIUM 7.8 HIGH
Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.