764 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-47196
Ghost Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-453 1 PoC

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_head` for a post.

CVE-2022-1445
snipe/snipe-it General
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.

CVE-2022-1457
neorazorx/facturascripts Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Store XSS in title parameter executing at EditUser Page & EditProducto page in GitHub repository neorazorx/facturascripts prior to 2022.04. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.

CVE-2022-3525
librenms/librenms General
9.0
CRITICAL
EPSS
0.0%
2022 CWE-502 1 PoC

Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.

CVE-2022-1346
causefx/organizr Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

CVE-2022-2063
nocodb/nocodb General
9.0
CRITICAL
EPSS
1.1%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVE-2022-1752
polonel/trudesk General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.

CVE-2022-47197
Ghost Web
9.0
CRITICAL
EPSS
1.8%
2022 CWE-453 3 PoCs

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_foot` for a post.

CVE-2022-2112
inventree/inventree General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-1236 1 PoC

Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.

CVE-2022-2890
yetiforcecompany/yetiforcecrm Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

CVE-2022-2111
inventree/inventree General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.

CVE-2022-47195
Ghost Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-453 1 PoC

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `facebook` field for a user.

CVE-2022-22115
docs Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. Since the Tag name is not being sanitized properly in the edit tag page, a low privileged attacker can store malicious scripts in the name of the Tag. In the worst case, the victim who inadvertently triggers the attack is a highly privileged administrator. The injected scripts can extract the Session ID, which can lead to full Account Takeover of the administrator, and privileges escalation.

CVE-2022-1514
neorazorx/facturascripts Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.

CVE-2022-1848
erudika/para General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository erudika/para prior to 1.45.11.

CVE-2022-0962
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-28712
AVideo Web
9.0
CRITICAL
EPSS
3.5%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-1045
polonel/trudesk Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-434 1 PoC

Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.

CVE-2022-47194
Ghost Web
9.0
CRITICAL
EPSS
0.6%
2022 CWE-453 1 PoC

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `twitter` field for a user.

CVE-2022-0946
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.