3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-35611
Software Genérico Web
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

A Cross-Site Request Forgery (CSRF) in MQTTRoute v3.3 and below allows attackers to create and remove dashboards.

CVE-2022-21243
Primavera Portfolio Management Web Database
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and 20.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Primavera Portfolio Management. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV

CVE-2022-3562
librenms/librenms Web
4.3
MEDIUM
EPSS
86.9%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

CVE-2022-4553
FL3R FeelBox Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables

CVE-2022-4089
Stock Management System Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-707 1 PoC

A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214324.

CVE-2022-3923
ActiveCampaign for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs.

CVE-2022-0226
livehelperchat/livehelperchat Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2022-2291
Hotel Management System Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability was found in SourceCodester Hotel Management System 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /ci_hms/search of the component Search. The manipulation of the argument search with the input "><script>alert("XSS")</script> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-4426
Mautic Integration for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

CVE-2022-0858
McAfee ePolicy Orchestrator (ePO) Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in.

CVE-2022-2460
WPDating Web Database Windows
4.3
MEDIUM
EPSS
4.4%
2022 1 PoC

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

CVE-2022-0708
Mattermost Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-200 1 PoC

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

CVE-2022-23180
Contact Form & Lead Form Elementor Builder Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings

CVE-2022-4408
thorsten/phpmyfaq Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

CVE-2022-4872
Chained Products Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ensure that the option to be updated belong to the plugin, allowing unauthenticated attackers to set arbitrary options to 'no'

CVE-2022-4004
Donation Button Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone numbers.

CVE-2022-3233
ikus060/rdiffweb Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.

CVE-2022-41413
Software Genérico Web
4.3
MEDIUM
EPSS
1.5%
2022 3 PoCs

perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into the Search function.

CVE-2022-41297
Db2U Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212.

CVE-2022-3876
Passwordstate Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-266 2 PoCs

A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This issue affects some unknown processing of the file /api/browserextension/UpdatePassword/ of the component API. The manipulation of the argument PasswordID leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier VDB-216245 was assigned to this vulnerability.