VendorsTrudesk Projecttrudeskany version
Vulnerabilities

Trudesk Project Trudesk any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2022-2023
Incorrect Use of Privileged APIs in polonel/trudesk
Published 2022-06-20 · Modified
10.0EPSS 0.032
CVE-2022-1770
Improper Privilege Management in polonel/trudesk
Published 2022-05-20 · Modified
9.9EPSS 0.025
CVE-2022-2128
Unrestricted Upload of File with Dangerous Type in polonel/trudesk
Published 2022-06-20 · Modified
9.8EPSS 0.029
CVE-2022-1775
Weak Password Requirements in polonel/trudesk
Published 2022-05-20 · Modified
9.8EPSS 0.022
CVE-2022-1931
Incorrect Synchronization in polonel/trudesk
Published 2022-05-31 · Modified
9.1EPSS 0.021
CVE-2022-1947
Use of Incorrect Operator in polonel/trudesk
Published 2022-05-31 · Modified
9.1EPSS 0.012
CVE-2022-1752
Unrestricted Upload of File with Dangerous Type in polonel/trudesk
Published 2022-05-21 · Modified
9.0EPSS 0.023
CVE-2022-1290
Stored XSS in "Name", "Group Name" & "Title" in polonel/trudesk
Published 2022-04-10 · Modified
9.0EPSS 0.017
CVE-2022-1045
Stored XSS viva .svg file upload in polonel/trudesk
Published 2022-04-11 · Modified
9.0EPSS 0.016
CVE-2022-1808
Execution with Unnecessary Privileges in polonel/trudesk
Published 2022-05-31 · Modified
8.8EPSS 0.035
CVE-2022-1803
Improper Restriction of Rendered UI Layers or Frames in polonel/trudesk
Published 2022-05-20 · Modified
8.4EPSS 0.016
CVE-2022-1754
Integer Overflow or Wraparound in polonel/trudesk
Published 2022-05-20 · Modified
8.4EPSS 0.010
CVE-2022-1044
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in polonel/trudesk
Published 2022-05-12 · Modified
8.2EPSS 0.009
CVE-2022-1926
Integer Overflow or Wraparound in polonel/trudesk
Published 2022-05-31 · Modified
7.6EPSS 0.010
CVE-2022-1728
Allowing long password leads to denial of service in polonel/trudesk in polonel/trudesk
Published 2022-05-16 · Modified
7.6EPSS 0.010
CVE-2022-1718
The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request in polonel/trudesk
Published 2022-05-16 · Modified
7.5EPSS 0.010
CVE-2022-1719
Reflected XSS on ticket filter function in polonel/trudesk
Published 2022-05-16 · Modified
5.5EPSS 0.007
CVE-2022-1893
Improper Removal of Sensitive Information Before Storage or Transfer in polonel/trudesk
Published 2022-05-31 · Modified
5.3EPSS 0.008