7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2111
inventree/inventree General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.

CVE-2022-2112
inventree/inventree General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-1236 1 PoC

Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.

CVE-2022-47197
Ghost Web
9.0
CRITICAL
EPSS
1.8%
2022 CWE-453 3 PoCs

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `codeinjection_foot` for a post.

CVE-2022-30284
Software Genérico General
9.0
CRITICAL
EPSS
14.2%
2022 1 PoC

In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input data that arrived over an untrusted network, and thus the CVSS score corresponds to an unrealistic use case. None of the NmapProcess documentation implies that this is an expected use case

CVE-2022-0946
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-2063
nocodb/nocodb General
9.0
CRITICAL
EPSS
1.1%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVE-2022-35401
RT-AX82U Web
9.0
CRITICAL
EPSS
0.1%
2022 CWE-324 1 PoC

An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to full administrative access to the device. An attacker would need to send a series of HTTP requests to exploit this vulnerability.

CVE-2022-28712
AVideo Web
9.0
CRITICAL
EPSS
3.5%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-1514
neorazorx/facturascripts Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.

CVE-2022-47195
Ghost Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-453 1 PoC

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `facebook` field for a user.

CVE-2022-32775
iota All-In-One Security Kit Web Windows
9.0
CRITICAL
EPSS
1.2%
2022 CWE-190 1 PoC

An integer overflow vulnerability exists in the web interface /action/ipcamRecordPost functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to memory corruption. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-32174
gogs Web
9.0
CRITICAL
EPSS
2.8%
2022 CWE-79 1 PoC

In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.

CVE-2022-0945
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-1345
causefx/organizr Web
9.0
CRITICAL
EPSS
0.3%
2022 CWE-434 1 PoC

Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

CVE-2022-1752
polonel/trudesk General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.

CVE-2022-1346
causefx/organizr Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.

CVE-2022-47194
Ghost Web
9.0
CRITICAL
EPSS
0.6%
2022 CWE-453 1 PoC

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escalation to administrator via XSS. To trigger this vulnerability, an attacker can send an HTTP request to inject Javascript in a post to trick an administrator into visiting the post.A stored XSS vulnerability exists in the `twitter` field for a user.

CVE-2022-1848
erudika/para General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository erudika/para prior to 1.45.11.

CVE-2022-0960
star7th/showdoc Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-2890
yetiforcecompany/yetiforcecrm Web
9.0
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.