3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-3419
Automatic User Roles Switcher Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 CWE-269 1 PoC

The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator

CVE-2022-32199
Software Genérico Web
6.5
MEDIUM
EPSS
13.1%
2022 1 PoC

db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in the file parameter.

CVE-2022-36779
PROSCEND M330-w / M330-W5 Web Networking
6.5
MEDIUM
EPSS
23.2%
2022 5 PoCs

PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-5G / M350-W5G / M350-6 / M350-W6 / M301-G / M301-GW ADVICE ICR 111WG / https://www.proscend.com/en/category/industrial-Cellular-Router/industrial-Cellular-Router.html https://cdn.shopify.com/s/files/1/0036/9413/3297/files/ADVICE_Industrial_4G_LTE_Cellular_Router_ICR111WG.pdf?v=1620814301

CVE-2022-26884
Apache DolphinScheduler Web
6.5
MEDIUM
EPSS
1.6%
2022 CWE-22 1 PoC

Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.

CVE-2022-3762
Booster for WooCommerce Web Windows
6.5
MEDIUM
EPSS
0.8%
2022 1 PoC

The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not validate files to download in some of its modules, which could allow ShopManager and Admin to download arbitrary files from the server even when they are not supposed to be able to (for example in multisite)

CVE-2022-21568
iReceivables Web Database
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: Access Request). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iReceivables accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2022-35136
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.

CVE-2022-4024
Registration Forms Web Windows
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

CVE-2022-45170
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user.

CVE-2022-34365
Wyse Management Suite Web
6.5
MEDIUM
EPSS
0.5%
2022 CWE-22 1 PoC

WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

CVE-2022-3946
Welcart e-Commerce Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.

CVE-2022-21584
Banking Trade Finance Web Database
6.4
MEDIUM
EPSS
1.5%
2022 1 PoC

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthoriz

CVE-2022-0966
star7th/showdoc Web
6.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Stored XSS via File Upload in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.4.10.

CVE-2022-4470
Widgets for Google Reviews Web Windows
6.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4503
openemr/openemr Web
6.4
MEDIUM
EPSS
0.8%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.0.2.

CVE-2022-47373
Pandora FMS Web
6.4
MEDIUM
EPSS
0.7%
2022 CWE-352 2 PoCs

Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper input validation/sanitization thus results in executing malicious JavaScript payload.

CVE-2022-21586
Banking Trade Finance Web Database
6.4
MEDIUM
EPSS
0.9%
2022 1 PoC

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthoriz

CVE-2022-21579
FLEXCUBE Universal Banking Web Database
6.4
MEDIUM
EPSS
1.5%
2022 1 PoC

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Universal Bankin

CVE-2022-41545
Software Genérico Web Networking
6.4
MEDIUM
EPSS
0.0%
2022 1 PoC

The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does not utilize transport security by default, this renders the administrative credentials vulnerable to eavesdropping by an adversary during every authenticated request made by a client to the router over a WLAN, or a LAN, should the adversary be able to perform a man-in-the-middle attack.

CVE-2022-40634
Crafter CMS Web
6.4
MEDIUM
EPSS
14.5%
2022 CWE-913 1 PoC

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI.