5623 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-24812
grafana DevOps Web
8.0
HIGH
EPSS
0.3%
2022 CWE-269 1 PoC

Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization. Because of the way the cache ID is constructed, the consequent requests with any API Key evaluate to the same permissions as the previous requests. This can lead to an escalation of privileges, when for example a first request is made with Admin permissions, and the second request with different API Key is made with Viewer permissions, the second

CVE-2022-0964
star7th/showdoc Web
8.0
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Stored XSS viva .webmv file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-2514
beancount/fava Web
8.0
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim.

CVE-2022-0121
hoppscotch/hoppscotch Web
8.0
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue affects hoppscotch/hoppscotch before 2.1.1.

CVE-2022-0723
microweber/microweber Web
8.0
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11.

CVE-2022-4839
usememos/memos Web
8.0
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-45938
Software Genérico Web
8.0
HIGH
EPSS
21.1%
2022 1 PoC

An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..

CVE-2022-39290
zoneminder Web
8.0
HIGH
EPSS
4.0%
2022 CWE-287 1 PoC

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to the Zoneminder web application. These modifications include replacing HTTP POST with an HTTP GET and removing the CSRF key from the request. An attacker can take advantage of this by using an HTTP GET request to perform actions with no CSRF protection. This could allow an attacker to cause an authenticated user to perform unexpected actions on the web application. Users are advised to upgrade as soon as possible. Th

CVE-2022-30577
TIBCO EBX Web
8.0
HIGH
EPSS
0.9%
2022 1 PoC

The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 6.0.0 through 6.0.8.

CVE-2022-39950
Fortinet FortiAnalyzer, FortiManager Web Networking
8.0
HIGH
EPSS
0.7%
2022 1 PoC

An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.

CVE-2022-2420
Web Manager Web
8.0
HIGH
EPSS
0.3%
2022 CWE-434 1 PoC

A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/uploader.php. The manipulation leads to unrestricted upload. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used.

CVE-2022-2418
Web Manager Web
8.0
HIGH
EPSS
0.3%
2022 CWE-434 1 PoC

A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used.

CVE-2022-3558
Import and export users and customers Web Windows
8.0
HIGH
EPSS
0.8%
2022 CWE-1236 1 PoC

The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.

CVE-2022-22776
TIBCO BusinessConnect Trading Community Management Web
8.0
HIGH
EPSS
0.6%
2022 1 PoC

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using these vulnerabilities requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.

CVE-2022-2523
beancount/fava Web
8.0
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.

CVE-2022-42896
Linux Kernel Web
8.0
HIGH
EPSS
0.4%
2022 CWE-416 6 PoCs

There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could execute code leaking kernel memory via Bluetooth if within proximity of the victim. We recommend upgrading past commit  https://www.google.com/url https://github.com/torvalds/linux/commit/711f8c3fb3db61897080468586b970c87c61d9e4 https://www.google.com/url

CVE-2022-4271
osticket/osticket Web
8.0
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.

CVE-2022-0269
yetiforcecompany/yetiforcecrm Web
8.0
HIGH
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.

CVE-2022-41266
Commerce Webservices 2.0 (Swagger UI) Web
8.0
HIGH
EPSS
0.4%
2022 CWE-79 2 PoCs

Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack.  As a result, an attacker may be able to steal user tokens and achieve a full account takeover including access to administrative tools in SAP Commerce.

CVE-2022-0930
microweber/microweber Web
8.0
HIGH
EPSS
0.5%
2022 CWE-434 1 PoC

File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.