3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-41312
SDS-3008 Series Industrial Ethernet Switch Web
4.3
MEDIUM
EPSS
1.1%
2022 CWE-79 2 PoCs

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="Switch Description", name "switch_description"

CVE-2022-3126
Frontend File Manager Plugin Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf

CVE-2022-0906
microweber/microweber Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.

CVE-2022-25839
url-js Web
4.3
MEDIUM
EPSS
0.2%
2022 3 PoCs

The package url-js before 2.1.0 are vulnerable to Improper Input Validation due to improper parsing, which makes it is possible for the hostname to be spoofed. http://\\\\\\\\localhost and http://localhost are the same URL. However, the hostname is not parsed as localhost, and the backslash is reflected as it is.

CVE-2022-3894
WP OAuth Server (OAuth Authentication) Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.

CVE-2022-3464
puppyCMS Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-707 2 PoCs

A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.

CVE-2022-0775
WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment

CVE-2022-21244
Primavera Portfolio Management Web Database
4.3
MEDIUM
EPSS
0.7%
2022 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and 20.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Portfolio Management accessib

CVE-2022-1332
Mattermost Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.

CVE-2022-3942
Sanitization Management System Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-707 2 PoCs

A vulnerability was found in SourceCodester Sanitization Management System and classified as problematic. This issue affects some unknown processing of the file php-sms/?p=request_quote. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-213449 was assigned to this vulnerability.

CVE-2022-43753
SUSE Linux Enterprise Module for SUSE Manager Server 4.2 Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-22 1 PoC

A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2, SUSE Linux Enterprise Module for SUSE Manager Server 4.3, SUSE Manager Server 4.2 allows remote attackers to read files available to the user running the process, typically tomcat. This issue affects: SUSE Linux Enterprise Module for SUSE Manager Server 4.2 hub-xmlrpc-api-0.7-150300.3.9.2, inter-server-sync-0.2.4-150300.8.25.2, locale-formula-0.3-150300.3.3.2, py27-compat-salt-3000.3-150300.7.7.26.2, python-urlgrabber-3.1

CVE-2022-4349
pwn Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-863 1 PoC

A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215109 was assigned to this vulnerability.

CVE-2022-46890
Software Genérico Web
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by a lack of checks performed by the /forums.php?action=post page).

CVE-2022-4013
Hospital Management Center Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-863 1 PoC

A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an unknown functionality of the file appointment.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213787.

CVE-2022-4014
FeehiCMS Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-863 1 PoC

A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The identifier of this vulnerability is VDB-213788.

CVE-2022-0348
pimcore/pimcore Web
4.3
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.

CVE-2022-1081
Microfinance Management System Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been declared as problematic. This vulnerability affects the file /mims/app/addcustomerHandler.php. The manipulation of the argument first_name, middle_name, and surname leads to cross site scripting. The attack can be initiated remotely.

CVE-2022-47130
Software Genérico Web
4.3
MEDIUM
EPSS
3.1%
2022 4 PoCs

A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page.

CVE-2022-48309
Sophos Connect Client Web
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.

CVE-2022-21532
JD Edwards EnterpriseOne Orchestrator Web Database
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator). Supported versions that are affected are 9.2.6.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).