3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-39050
OTRS Web Windows
4.6
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be run later by any other agent when clicking the customer URL link. Then the stored JavaScript is executed in the context of OTRS. The same issue applies for the usage of external data sources e.g. database or ldap

CVE-2022-21338
Communications Convergence Web Database
4.6
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: General Framework). The supported version that is affected is 3.0.2.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Convergence. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Convergence accessible data as well as unauthorized rea

CVE-2022-0743
getgrav/grav Web
4.6
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.

CVE-2022-3205
Red Hat Ansible Automation Platform 1.2 DevOps Web
4.6
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection

CVE-2022-48429
Hub Web
4.6
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible

CVE-2022-25873
vuetify Web
4.6
MEDIUM
EPSS
0.6%
2022 3 PoCs

The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.

CVE-2022-4562
Meks Flexible Shortcodes Web Windows
4.6
MEDIUM
EPSS
0.3%
2022 1 PoC

The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-2871
notrinos/notrinoserp Web
4.6
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository notrinos/notrinoserp prior to 0.7.

CVE-2022-0238
phoronix-test-suite/phoronix-test-suite Web
4.5
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2022-39277
glpi Web
4.5
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. External links are not properly sanitized and can therefore be used for a Cross-Site Scripting (XSS) attack. This issue has been patched, please upgrade to GLPI 10.0.4. There are currently no known workarounds.

CVE-2022-21595
MySQL Server Web Database
4.4
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-1928
go-gitea/gitea Web
4.4
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.

CVE-2022-2387
Easy Digital Downloads – Simple eCommerce for Selling Digital Files Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack

CVE-2022-2913
Login No Captcha reCAPTCHA Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.

CVE-2022-3994
Authenticator Web Windows
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, which may deny other users access to the functionality in certain configurations.

CVE-2022-3451
Product Stock Manager Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options

CVE-2022-0763
microweber/microweber Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-3098
Login Block IPs Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-4148
WP OAuth Server (OAuth Authentication) Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.

CVE-2022-3151
WP Custom Cursors Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.