VulnSea

portfolio vulnerabilities

CVEs whose affected-version data names the portfolio package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2022-24255High· 8.8
4y ago

Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

Twilightextensis · portfolioEPSS 1.4%via NVD
CVE-2022-24254High· 8.8
4y ago

An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.

An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.

Twilightextensis · portfolioEPSS 2.6%via NVD
CVE-2022-24253High· 8.8
4y ago

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

Twilightextensis · portfolioEPSS 1.3%via NVD
CVE-2022-24252High· 8.8
4y ago

An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.

An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.

Twilightextensis · portfolioEPSS 2.3%via NVD
CVE-2022-24251High· 8.8
4y ago

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.

Twilightextensis · portfolioEPSS 1.3%via NVD
portfolio vulnerabilities (CVEs) · VulnSea