13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2018-16874
golang Web
6.8
MEDIUM
EPSS
5.7%
2018 CWE-20 1 PoC

In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at https://golang.org/cmd/go/#hdr-Module_aware_go_get). The attacker can cause an arbitrary filesystem write, which can lead to code execution.

CVE-2022-47909
Checkmk Web
6.8
MEDIUM
EPSS
0.3%
2022 CWE-20 1 PoC

Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application's core from localhost.

CVE-2022-3267
ikus060/rdiffweb Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.

CVE-2022-1351
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Stored XSS in Tooltip in GitHub repository pimcore/pimcore prior to 10.4.

CVE-2022-0911
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE-2022-0893
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE-2022-46367
FTP server Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation.

CVE-2022-21551
GoldenGate Web Database
6.8
MEDIUM
EPSS
1.6%
2022 1 PoC

Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate). The supported version that is affected is 21c: prior to 21.7.0.0.0; 19c: prior to 19.1.0.0.220719. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 6.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

CVE-2022-0571
phoronix-test-suite/phoronix-test-suite Web
6.8
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.

CVE-2022-2016
neorazorx/facturascripts Web
6.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.1.

CVE-2022-1163
mineweb/minewebcms Web
6.8
MEDIUM
EPSS
0.6%
2022 CWE-79 3 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.

CVE-2022-39187
FTP server Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Rumpus - FTP server version 9.0.7.1 has a Reflected cross-site scripting (RXSS) vulnerability through unspecified vectors.

CVE-2022-0020
Cortex XSOAR Web Networking
6.8
MEDIUM
EPSS
1.0%
2022 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the payload during normal operations. This issue impacts: All builds of Cortex XSOAR 6.1.0; Cortex XSOAR 6.2.0 builds earlier than build 1958888.

CVE-2022-4793
Blog Designer Web Windows
6.8
MEDIUM
EPSS
0.5%
2022 1 PoC

The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-1726
wenzhixin/bootstrap-table Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.

CVE-2022-0929
microweber/microweber Web
6.8
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-4761
Post Views Count (Support caching plugins!) Web Windows
6.8
MEDIUM
EPSS
0.5%
2022 1 PoC

The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-46368
FTP server Web
6.8
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.

CVE-2022-4512
Better Font Awesome Web Windows
6.8
MEDIUM
EPSS
0.7%
2022 1 PoC

The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-0274
orchardcms/orchardcore Web
6.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.