Skip to main content

Vendor archive

hyland CVEs

Beta · best-effort

31 CVEs tagged to vendor hyland12 Critical, 14 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-58127

Published Jul 1, 2026

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any au…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-58126

Published Jul 1, 2026

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .N…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-26336

Published Feb 19, 2026

Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" endpoint, thus leading to the di…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2024-40347

Published Jul 20, 2024

A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute arbitrary code in the context of a user's browser via injec…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49964

Published Dec 11, 2023

An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Si…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32828

Published Jan 5, 2023

The Nuxeo Platform is an open source content management platform for building business applications. In version 11.5.109, the `oauth2` REST API is vulnerable to Reflected Cross-Si…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23342

Published Jun 21, 2022

The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25260

Published Sep 11, 2020

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows remote attack…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25259

Published Sep 11, 2020

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It uses XML deserializa…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25258

Published Sep 11, 2020

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It uses ASP.NET BinaryF…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25257

Published Sep 11, 2020

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows XXE attacks f…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25256

Published Sep 11, 2020

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. PKI certificates have a…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25255

Published Sep 11, 2020

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows remote attack…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25254

Published Sep 11, 2020

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25253

Published Sep 11, 2020

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25252

Published Sep 11, 2020

An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. CSRF can be use…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25251

Published Sep 11, 2020

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Client-side authenticat…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25250

Published Sep 11, 2020

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Client applications can…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25249

Published Sep 11, 2020

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. The server typically lo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25248

Published Sep 11, 2020

An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Directory trave…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25247

Published Sep 11, 2020

An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. Directory traversal exists for writing to files, as demonstrated by the FileName parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19629

Published Jul 16, 2019

A Denial of Service vulnerability in the ImageNow Server service in Hyland Perceptive Content Server before 7.1.5 allows an attacker to crash the service via a TCP connection.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2