3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-22760
Firefox Web
6.5
MEDIUM
EPSS
0.2%
2022 2 PoCs

When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVE-2022-0374
livehelperchat/livehelperchat Web
6.5
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

CVE-2022-31064
bigbluebutton Web
6.5
MEDIUM
EPSS
0.8%
2022 CWE-79 2 PoCs

BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the JavaScript will be executed. This issue has been addressed in version 2.4.8 and 2.5.0. There are no known workarounds for this issue.

CVE-2022-3926
WP OAuth Server (OAuth Authentication) Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID

CVE-2022-34125
Software Genérico Web
6.5
MEDIUM
EPSS
9.4%
2022 1 PoC

front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter.

CVE-2022-34662
Apache DolphinScheduler Web
6.5
MEDIUM
EPSS
1.0%
2022 CWE-22 1 PoC

When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher

CVE-2022-20816
Cisco Unified Communications Manager Web Networking
6.5
MEDIUM
EPSS
0.7%
2022 CWE-22 1 PoC

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to delete arbitrary files from an affected system. This vulnerability exists because the affected software does not properly validate HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker to delete arbitrary files from the affected system.

CVE-2022-45962
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.5%
2022 1 PoC

Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.

CVE-2022-32761
AVideo Web
6.5
MEDIUM
EPSS
2.7%
2022 CWE-73 1 PoC

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-4443
BruteBank Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The BruteBank WordPress plugin before 1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVE-2022-40488
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF).

CVE-2022-3930
Directorist Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.

CVE-2022-4163
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.6%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before concatenating it to an SQL query in 2_deactivate.php and 4_activate.php, respectively. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2022-3882
Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-3247
Blog2Social: Social Media Auto Post & Scheduler Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 CWE-918 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks

CVE-2022-21636
Applications Framework Web Database
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Session Management). Supported versions that are affected are 12.2.6-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2022-36783
FireFlow A32.0 Web
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malicious user changes the request from POST to GET and sends the URL to another user (victim). JavaScript code is executed on the browser of the other user.

CVE-2022-1223
phpipam/phpipam Web
6.5
MEDIUM
EPSS
0.3%
2022 CWE-863 1 PoC

Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

CVE-2022-3883
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2022-36779
PROSCEND M330-w / M330-W5 Web Networking
6.5
MEDIUM
EPSS
23.2%
2022 5 PoCs

PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-5G / M350-W5G / M350-6 / M350-W6 / M301-G / M301-GW ADVICE ICR 111WG / https://www.proscend.com/en/category/industrial-Cellular-Router/industrial-Cellular-Router.html https://cdn.shopify.com/s/files/1/0036/9413/3297/files/ADVICE_Industrial_4G_LTE_Cellular_Router_ICR111WG.pdf?v=1620814301