13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-3632
OAuth Client by DigitialPixies Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions.

CVE-2022-28710
AVideo Web
6.5
MEDIUM
EPSS
2.7%
2022 CWE-73 1 PoC

An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-21252
WebLogic Server Web Database
6.5
MEDIUM
EPSS
1.0%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity im

CVE-2022-4161
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.7%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_start POST parameter before concatenating it to an SQL query in copy-gallery-images.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-24189
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. Removing the value causes all requests to succeed, bypassing authorization and session management. The impact of this vulnerability allows an attacker POST api calls with other users unique identifiers and enumerate information of all other end-users.

CVE-2022-4384
Stream Web Windows
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

The Stream WordPress plugin before 3.9.2 does not prevent users with little privileges on the site (like subscribers) from using its alert creation functionality, which may enable them to leak sensitive information.

CVE-2022-40488
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF).

CVE-2022-4443
BruteBank Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The BruteBank WordPress plugin before 1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVE-2022-4548
Optimize images ALT Text (alt tag) & names for SEO using AI Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVE-2022-28172
DS-A71024/48/72R,DS-A80624S,DS-A81016S,DS-A72024/72R,DS-A80316S,DS-A82024D Web
6.5
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device.

CVE-2022-2470
microweber/microweber Web
6.5
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.

CVE-2022-4164
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.6%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_multiple_files_for_post POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-3232
ikus060/rdiffweb Web
6.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.

CVE-2022-21561
JD Edwards EnterpriseOne Tools Web Database
6.5
MEDIUM
EPSS
0.5%
2022 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). Supported versions that are affected are 9.2.6.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2022-4363
Wholesale Market Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack

CVE-2022-3926
WP OAuth Server (OAuth Authentication) Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID

CVE-2022-21518
Health Sciences Data Management Workbench Web Database
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: User Interface). Supported versions that are affected are 2.4.8.7 and 2.5.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences Data Management Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Health Sciences Data Management Workbench accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).

CVE-2022-45437
Pandora FMS Web
6.5
MEDIUM
EPSS
0.7%
2022 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandora FMS v765 on all allows Cross-Site Scripting (XSS). A user with edition privileges can create a Payload in the reporting dashboard module. An admin user can observe the Payload without interaction and attacker can get information.

CVE-2022-3538
Webmaster Tools Verification Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 CWE-862 1 PoC

The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling plugins, allowing unauthenticated users to disable arbitrary plugins

CVE-2022-21467
Agile PLM Framework Web Database
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).