CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)#### Summary An authenticated user with the HR "Manage Employees" permission (`SA_EMPLOYEE`) can upload a file with an arbitrary extension through the employee **Documents** tab. The handler writes the raw client-supplied filename — extension intact — into a web served directory with no extension, MIME, or content validation, so a `.php` file is stored under the web root and executes as code, yielding remote code execution on the server. #### Details The document-upload branch in `hrm/manage/em… | CVSS-v3.1 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-24788HIGH | NotrinosERP vulnerable to SQL InjectionNotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php. CWE-89Mar 23, 2023 | CVSS8.8v3.1 | EPSS3.09% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-2927CRITICAL | Weak Password Requirements in notrinos/notrinoserpWeak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7. CWE-521Aug 22, 2022 | CVSS9.8v3.1 | EPSS0.772% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-2921HIGH | Exposure of Private Personal Information to an Unauthorized Actor in notrinos/notrinoserpExposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected functionality such as create/update companies, install/update languages, install/activate extensions, install/activate themes and other permissive actions. CWE-359Aug 21, 2022 | CVSS8.8v3.1 | EPSS1.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-2871MEDIUM | Cross-site Scripting (XSS) - Stored in notrinos/notrinoserpCross-site Scripting (XSS) - Stored in GitHub repository notrinos/notrinoserp prior to 0.7. CWE-79Aug 17, 2022 | CVSS5.4v3.1 | EPSS0.55% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |