94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1045
polonel/trudesk Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-434 1 PoC

Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.

CVE-2022-47194
Ghost Web
9.0
CRITICAL
EPSS
0.6%
2022 CWE-453 1 PoC

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `twitter` field for a user.

CVE-2022-0946
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-2022
nocodb/nocodb Web
9.0
CRITICAL
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.

CVE-2022-0960
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-21122
metacalc Web
9.0
CRITICAL
EPSS
1.1%
2022 1 PoC

The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.

CVE-2022-1909
causefx/organizr Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository causefx/organizr prior to 2.1.2200.

CVE-2022-32177
gin-vue-admin Web
9.0
CRITICAL
EPSS
0.7%
2022 CWE-434 1 PoC

In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover.

CVE-2022-1344
causefx/organizr Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

CVE-2022-2036
francoisjacquet/rosariosis Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1.

CVE-2022-0965
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Stored XSS viva .ofd file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-32176
gin-vue-admin Web
9.0
CRITICAL
EPSS
0.6%
2022 CWE-434 1 PoC

In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin's cookie leading to account takeover.

CVE-2022-47196
Ghost Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-453 1 PoC

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_head` for a post.

CVE-2022-1445
snipe/snipe-it General
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.

CVE-2022-3525
librenms/librenms General
9.0
CRITICAL
EPSS
0.0%
2022 CWE-502 1 PoC

Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.

CVE-2022-2063
nocodb/nocodb General
9.0
CRITICAL
EPSS
1.1%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVE-2022-47197
Ghost Web
9.0
CRITICAL
EPSS
1.8%
2022 CWE-453 3 PoCs

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_foot` for a post.

CVE-2022-2112
inventree/inventree General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-1236 1 PoC

Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.

CVE-2022-2111
inventree/inventree General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.

CVE-2022-47195
Ghost Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-453 1 PoC

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `facebook` field for a user.