CVE-2022-0942

CRITICAL Year: 2022
CVSS v3 Score
9.4
Critical
CVSS v2 Score
3.5
Low

Vulnerability Description

Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVSS:9.4(Critical)

A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

CWE-792019
CVSS:9.4(Critical)

stored xss due to unsantized anchor url in GitHub repository alvarotrigo/fullpage.js prior to 4.0.4. stored xss .

CWE-792022
CVSS:9.4(Critical)

Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in...

CWE-792022
CVSS:9.4(Critical)

Cross-site Scripting (XSS) - Generic in GitHub repository erudika/para prior to v1.45.11.

CWE-792022
CVSS:9.3(Critical)

A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspecified page, which could let a malicious user obtain sensitive information.

CWE-792014
CVSS:9.3(Critical)

Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-9647.

CWE-792019