13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-3511
Awesome Support Web Windows
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector

CVE-2022-4266
Bulk Delete Users by Email Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Bulk Delete Users by Email WordPress plugin through 1.2 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete non admin users by knowing their email via a CSRF attack

CVE-2022-1225
phpipam/phpipam Web
6.5
MEDIUM
EPSS
0.2%
2022 CWE-266 1 PoC

Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.

CVE-2022-4239
Workreap Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.

CVE-2022-21636
Applications Framework Web Database
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Session Management). Supported versions that are affected are 12.2.6-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2022-4166
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.7%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the addCountS POST parameter before concatenating it to an SQL query in 4_activate.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-28282
Thunderbird Web
6.5
MEDIUM
EPSS
5.6%
2022 4 PoCs

By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVE-2022-4844
usememos/memos Web
6.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4153
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.6%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the upload[] POST parameter before concatenating it to an SQL query in get-data-create-upload-v10.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-3419
Automatic User Roles Switcher Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 CWE-269 1 PoC

The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator

CVE-2022-1223
phpipam/phpipam Web
6.5
MEDIUM
EPSS
0.3%
2022 CWE-863 1 PoC

Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

CVE-2022-25937
glance Web
6.5
MEDIUM
EPSS
0.7%
2022 CWE-22 2 PoCs

Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory. This is related to but distinct from the vulnerability reported in [CVE-2018-3715](https://security.snyk.io/vuln/npm:glance:20180129).

CVE-2022-3961
Directorist Web Windows
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information.

CVE-2022-2130
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
46.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.

CVE-2022-2174
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
27.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.

CVE-2022-31629
PHP Web
6.5
MEDIUM
EPSS
15.4%
2022 CWE-20 2 PoCs

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVE-2022-4159
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
1.0%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-3677
Advanced Import : One Click Import for WordPress or Theme Demo Data Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arbitrary plugins from WordPress.org, and activate arbitrary ones from the blog via CSRF attacks

CVE-2022-2401
Mattermost Web
6.5
MEDIUM
EPSS
0.3%
2022 CWE-200 1 PoC

Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.

CVE-2022-3873
jgraph/drawio Web
6.5
MEDIUM
EPSS
0.7%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository jgraph/drawio prior to 20.5.2.