Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
onlyoffice document server vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-30186
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 up to and including 7.3.2 allows remote malicious users to run arbitrary code via crafted JavaScript file.
Onlyoffice Document Server
9.8
CVSSv3
CVE-2023-30187
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 up to and including 7.3.2 allows remote malicious users to run arbitrary code via crafted JavaScript file.
Onlyoffice Document Server
9.8
CVSSv3
CVE-2021-43445
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key.
Onlyoffice Server
9.8
CVSSv3
CVE-2022-29776
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.
Onlyoffice Core
Onlyoffice Document Server
1 Github repository
9.8
CVSSv3
CVE-2022-29777
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
Onlyoffice Core
Onlyoffice Document Server
1 Github repository
9.8
CVSSv3
CVE-2021-40864
The Translate plugin 6.1.x up to and including 6.3.x prior to 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.
Onlyoffice Google Translate
9.8
CVSSv3
CVE-2021-25830
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker...
Onlyoffice Document Server
9.8
CVSSv3
CVE-2021-25831
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of the crafted file from PPTT into PPTX format. Using the chain of two other bugs related to improper string handling, a remote attacke...
Onlyoffice Document Server
9.8
CVSSv3
CVE-2021-25833
A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain ...
Onlyoffice Document Server
9.8
CVSSv3
CVE-2021-25832
A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer.
Onlyoffice Document Server
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »