3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-2724
Employee Management System Web Database
6.3
MEDIUM
EPSS
0.4%
2022 CWE-89 2 PoCs

A vulnerability was found in SourceCodester Employee Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /process/aprocess.php. The manipulation of the argument mailuid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205837 was assigned to this vulnerability.

CVE-2022-3122
Clinics Patient Management System Web Database
6.3
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file medicine_details.php. The manipulation of the argument medicine leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-207854 is the identifier assigned to this vulnerability.

CVE-2022-2774
Library Management System Web Database
6.3
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability was found in SourceCodester Library Management System. It has been declared as critical. This vulnerability affects unknown code of the file librarian/student.php. The manipulation of the argument title leads to sql injection. The attack can be initiated remotely. VDB-206170 is the identifier assigned to this vulnerability.

CVE-2022-2297
Clinics Patient Management System Web
6.3
MEDIUM
EPSS
70.0%
2022 CWE-434 1 PoC

A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.php?user_id=1. The manipulation of the argument profile_picture with the input <?php phpinfo();?> leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-2751
Company Website CMS Web
6.3
MEDIUM
EPSS
0.3%
2022 CWE-434 1 PoC

A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-206024.

CVE-2022-2770
Simple Online Book Store System Web Database
6.3
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Book Store System. Affected is an unknown function of the file /obs/book.php. The manipulation of the argument bookisbn leads to sql injection. It is possible to launch the attack remotely. VDB-206166 is the identifier assigned to this vulnerability.

CVE-2022-3732
Ehoney Web Database
6.3
MEDIUM
EPSS
0.2%
2022 CWE-707 1 PoC

A vulnerability was found in seccome Ehoney and classified as critical. Affected by this issue is some unknown functionality of the file /api/v1/bait/set. The manipulation of the argument Payload leads to sql injection. The attack may be launched remotely. VDB-212414 is the identifier assigned to this vulnerability.

CVE-2022-1439
microweber/microweber Web ⚡ nuclei
6.3
MEDIUM
EPSS
43.8%
2022 CWE-79 1 PoC

Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to press "tab" but there is probably a paylaod that runs without user interaction.

CVE-2022-1584
microweber/microweber Web
6.3
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim

CVE-2022-2677
Apartment Visitor Management System Web Database
6.3
MEDIUM
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been classified as critical. This affects an unknown part of the file index.php. The manipulation of the argument username with the input ' AND (SELECT 4955 FROM (SELECT(SLEEP(5)))RSzF) AND 'htiy'='htiy leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205665 was assigned to this vulnerability.

CVE-2022-4257
Web Management System Web
6.3
MEDIUM
EPSS
2.7%
2022 CWE-707 1 PoC

A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknown processing of the file cgi-bin/jumpto.php of the component GET Parameter Handler. The manipulation of the argument hostname leads to argument injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214631.

CVE-2022-1730
jgraph/drawio Web
6.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4.

CVE-2022-26947
Software Genérico Web
6.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets executed by the web browser in the context of the vulnerable web application.

CVE-2022-0937
star7th/showdoc Web
6.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-2578
Garage Management System Web
6.3
MEDIUM
EPSS
0.3%
2022 CWE-284 1 PoC

A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This issue affects some unknown processing of the file /php_action/createUser.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-4276
House Rental System Web
6.3
MEDIUM
EPSS
0.2%
2022 CWE-266 1 PoC

A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-engine.php of the component POST Request Handler. The manipulation of the argument id_photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214772.

CVE-2022-2909
Simple and Nice Shopping Cart Script Web
6.3
MEDIUM
EPSS
0.4%
2022 CWE-434 1 PoC

A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206845 was assigned to this vulnerability.

CVE-2022-4409
thorsten/phpmyfaq Web
6.3
MEDIUM
EPSS
0.2%
2022 CWE-614 1 PoC

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

CVE-2022-4375
MCMS Web Database ⚡ nuclei
6.3
MEDIUM
EPSS
26.2%
2022 CWE-707 2 PoCs

A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the argument sqlWhere leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.2.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215196.

CVE-2022-30626
Chcnav - P5E GNSS Web
6.3
MEDIUM
EPSS
0.1%
2022 2 PoCs

Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component, and a password in clear text.