3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-3098
Login Block IPs Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-2450
reSmush.it : the only free Image Optimizer & compress plugin Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.

CVE-2022-29915
Firefox Web
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.

CVE-2022-2912
Craw Data Web Windows
4.3
MEDIUM
EPSS
0.4%
2022 CWE-918 1 PoC

The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logged in admin change the url value performing unwanted crawls on third-party sites (SSRF).

CVE-2022-32205
https://github.com/curl/curl Web
4.3
MEDIUM
EPSS
2.6%
2022 CWE-770 1 PoC

A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to avoid sending crazy large requests (1048576 bytes) and instead returns an error.This denial state might remain for as long as the same cookies are kept, match and haven't expired. Due to cookie matching rules, a server on `foo.example.com` can set coo

CVE-2022-1102
Royale Event Management System Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-79 2 PoCs

A vulnerability classified as problematic has been found in SourceCodester Royale Event Management System 1.0. Affected is an unknown function of the file /royal_event/companyprofile.php. The manipulation of the argument companyname/regno/companyaddress/companyemail leads to cross site scripting. It is possible to launch the attack remotely. VDB-195786 is the identifier assigned to this vulnerability.

CVE-2022-2846
Calendar Event Multi View Web Windows
4.3
MEDIUM
EPSS
3.0%
2022 CWE-862 2 PoCs

The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.

CVE-2022-0282
microweber/microweber Web
4.3
MEDIUM
EPSS
0.7%
2022 CWE-79 1 PoC

Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-3017
froxlor/froxlor Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.

CVE-2022-2406
Mattermost Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-400 1 PoC

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.

CVE-2022-0510
pimcore/pimcore Web
4.3
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Packagist pimcore/pimcore prior to 10.3.1.

CVE-2022-4019
Playbooks Plugin Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-770 1 PoC

A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.

CVE-2022-21948
paste Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in paste allows remote attackers to place Javascript into SVG files. This issue affects: openSUSE paste paste version b57b9f87e303a3db9465776e657378e96845493b and prior versions.

CVE-2022-41311
SDS-3008 Series Industrial Ethernet Switch Web
4.3
MEDIUM
EPSS
1.1%
2022 CWE-79 2 PoCs

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="webLocationMessage_text" name="webLocationMessage_text"

CVE-2022-41312
SDS-3008 Series Industrial Ethernet Switch Web
4.3
MEDIUM
EPSS
1.1%
2022 CWE-79 2 PoCs

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="Switch Description", name "switch_description"

CVE-2022-3850
Find and Replace All Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack

CVE-2022-22762
Firefox Web
4.3
MEDIUM
EPSS
0.3%
2022 2 PoCs

Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This could have been abused to trick the user. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVE-2022-41313
SDS-3008 Series Industrial Ethernet Switch Web
4.3
MEDIUM
EPSS
2.3%
2022 CWE-79 2 PoCs

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="switch_contact"

CVE-2022-4354
pb-cms Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-707 1 PoC

A vulnerability was found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /blog/comment of the component Message Board. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-215114 is the identifier assigned to this vulnerability.

CVE-2022-4549
Tickera Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.