3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-29468
AVideo Web
8.8
HIGH
EPSS
1.3%
2022 CWE-352 1 PoC

A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-1578
My wpdb Web Database Windows
8.8
HIGH
EPSS
0.2%
2022 1 PoC

The My wpdb WordPress plugin before 2.5 is missing CSRF check when running SQL queries, which could allow attacker to make a logged in admin run arbitrary SQL query via a CSRF attack

CVE-2022-22758
Firefox Web
8.8
HIGH
EPSS
0.2%
2022 2 PoCs

When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVE-2022-34020
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2022 2 PoCs

Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows attackers to add new admin users to the platform or other unspecified impacts.

CVE-2022-34468
Firefox Web
8.8
HIGH
EPSS
0.5%
2022 1 PoC

An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVE-2022-1802
Firefox ESR Web
8.8
HIGH
EPSS
67.9%
2022 1 PoC

If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.

CVE-2022-3359
Shortcodes and extra features for Phlox theme Web Windows
8.8
HIGH
EPSS
0.8%
2022 1 PoC

The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

CVE-2022-22755
Firefox Web
8.8
HIGH
EPSS
0.8%
2022 2 PoCs

By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97.

CVE-2022-46499
Software Genérico Web Database
8.8
HIGH
EPSS
0.2%
2022 1 PoC

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.

CVE-2022-29557
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2022 1 PoC

LexisNexis Firco Compliance Link 3.7 allows CSRF.

CVE-2022-0690
microweber/microweber Web
8.8
HIGH
EPSS
0.9%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-32774
Foxit Reader Web
8.8
HIGH
EPSS
0.5%
2022 CWE-416 1 PoC

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely deleting objects associated with pages, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

CVE-2022-35196
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2022 1 PoC

TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.

CVE-2022-24780
iTop Web
8.8
HIGH
EPSS
20.7%
2022 CWE-94 3 PoCs

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds.

CVE-2022-3246
Blog2Social: Social Media Auto Post & Scheduler Web Database Windows
8.8
HIGH
EPSS
0.8%
2022 CWE-89 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers

CVE-2022-37209
Software Genérico Web Database
8.8
HIGH
EPSS
1.1%
2022 2 PoCs

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-3861
Betheme Web Windows
8.8
HIGH
EPSS
4.6%
2022 CWE-502 1 PoC

The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and mfn-items-import parameters passed through the mfn_builder_import, mfn_builder_import_page, importdata, importsinglepage, and importfromclipboard functions. This makes it possible for authenticated attackers, with subscriber level permissions and above to inject a PHP Object. The additional presence of a POP chain would make it possible for attackers to execute code, retrieve sensitive data,

CVE-2022-45942
Software Genérico Web
8.8
HIGH
EPSS
3.9%
2022 1 PoC

A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.

CVE-2022-44849
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2022 1 PoC

A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account.

CVE-2022-23642
sourcegraph Web Networking
8.8
HIGH
EPSS
85.3%
2022 CWE-94 3 PoCs

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a remote system. Exploitation of this vulnerability depends on how Sourcegraph is deployed. An attacker able to make HTTP requests to internal services like gitserver is able to exploit it. This issue is