CVE-2022-0506

CVSS v3 Score
7.7
High
CVSS v2 Score
3.5
Low

Vulnerability Description

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.

CVSS:7.7(High)

Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel allows media files to be uploaded. As a default, SVG is an allowed file type fo...

CWE-792024
CVSS:7.8(High)

Certain NETGEAR devices are affected by stored XSS. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F be...

CWE-792017
CVSS:7.8(High)

A vulnerability has been identified in SCALANCE M875 (All versions). An attacker with access to the local file system might obtain passwords for administrative users. Successful exploitation requires ...

CWE-792018
CVSS:7.8(High)

Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.

CWE-792020
CVSS:7.8(High)

xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.

CWE-792021
CVSS:7.8(High)

The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.

CWE-792021