764 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1752
polonel/trudesk General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.

CVE-2022-1514
neorazorx/facturascripts Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.

CVE-2022-1848
erudika/para General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository erudika/para prior to 1.45.11.

CVE-2022-28712
AVideo Web
9.0
CRITICAL
EPSS
3.5%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-1045
polonel/trudesk Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-434 1 PoC

Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.

CVE-2022-47194
Ghost Web
9.0
CRITICAL
EPSS
0.6%
2022 CWE-453 1 PoC

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `twitter` field for a user.

CVE-2022-0946
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-2022
nocodb/nocodb Web
9.0
CRITICAL
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.

CVE-2022-0960
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-21122
metacalc Web
9.0
CRITICAL
EPSS
1.1%
2022 1 PoC

The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.

CVE-2022-1909
causefx/organizr Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200.

CVE-2022-32177
gin-vue-admin Web
9.0
CRITICAL
EPSS
0.7%
2022 CWE-434 1 PoC

In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover.

CVE-2022-1344
causefx/organizr Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

CVE-2022-2036
francoisjacquet/rosariosis Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1.

CVE-2022-0965
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Stored XSS viva .ofd file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-32176
gin-vue-admin Web
9.0
CRITICAL
EPSS
0.6%
2022 CWE-434 1 PoC

In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin's cookie leading to account takeover.

CVE-2022-47196
Ghost Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-453 1 PoC

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_head` for a post.

CVE-2022-1445
snipe/snipe-it General
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.

CVE-2022-3525
librenms/librenms General
9.0
CRITICAL
EPSS
0.0%
2022 CWE-502 1 PoC

Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.

CVE-2022-2063
nocodb/nocodb General
9.0
CRITICAL
EPSS
1.1%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.