3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-33328
R1510 Web
9.1
CRITICAL
EPSS
3.5%
2022 CWE-78 1 PoC

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.The `/ajax/remove/` API is affected by a command injection vulnerability.

CVE-2022-25784
SiteManager Web
9.1
CRITICAL
EPSS
0.7%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7.

CVE-2022-42484
FreshTomato Web
9.1
CRITICAL
EPSS
0.6%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-1514
neorazorx/facturascripts Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.

CVE-2022-0946
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-47197
Ghost Web
9.0
CRITICAL
EPSS
1.8%
2022 CWE-453 3 PoCs

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_foot` for a post.

CVE-2022-1909
causefx/organizr Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200.

CVE-2022-0960
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-28712
AVideo Web
9.0
CRITICAL
EPSS
3.5%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-32176
gin-vue-admin Web
9.0
CRITICAL
EPSS
0.6%
2022 CWE-434 1 PoC

In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin's cookie leading to account takeover.

CVE-2022-0945
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-32775
iota All-In-One Security Kit Web Windows
9.0
CRITICAL
EPSS
1.2%
2022 CWE-190 1 PoC

An integer overflow vulnerability exists in the web interface /action/ipcamRecordPost functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to memory corruption. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-47196
Ghost Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-453 1 PoC

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_head` for a post.

CVE-2022-48311
Software Genérico Web
9.0
CRITICAL
EPSS
0.8%
2022 1 PoC

**UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticated attacker to inject their own script into the page via HTTP configuration page. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2022-1064
forkcms/forkcms Web Database
9.0
CRITICAL
EPSS
0.3%
2022 CWE-89 1 PoC

SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.

CVE-2022-2890
yetiforcecompany/yetiforcecrm Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

CVE-2022-31358
Software Genérico Web
9.0
CRITICAL
EPSS
0.9%
2022 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.

CVE-2022-1045
polonel/trudesk Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-434 1 PoC

Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.

CVE-2022-32174
gogs Web
9.0
CRITICAL
EPSS
2.8%
2022 CWE-79 1 PoC

In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.

CVE-2022-0965
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Stored XSS viva .ofd file upload in GitHub repository star7th/showdoc prior to 2.10.4.