3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-3282
Drag and Drop Multiple File Upload – Contact Form 7 Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.

CVE-2022-21383
Enterprise Session Border Controller Web Database
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Log). Supported versions that are affected are 8.4 and 9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Session Border Controller. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/

CVE-2022-3223
jgraph/drawio Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.

CVE-2022-35507
Software Genérico Web ⚡ nuclei
4.3
MEDIUM
EPSS
14.3%
2022 1 PoC

A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow injection of response headers with %0d. This is fixed in pve-http-server 4.1-3.

CVE-2022-2405
WP Popup Builder – Popup Forms , Marketing PoPuP & Newsletter Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup

CVE-2022-4683
usememos/memos Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-614 1 PoC

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-3121
Online Employee Leave Management System Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addemployee.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The identifier VDB-207853 was assigned to this vulnerability.

CVE-2022-26382
Firefox Web
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98.

CVE-2022-3995
Wallet for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lock_unlock_terawallet AJAX action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to lock/unlock other users wallets.

CVE-2022-0515
crater-invoice/crater Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.

CVE-2022-4944
KodExplorer Web
4.3
MEDIUM
EPSS
2.3%
2022 CWE-352 4 PoCs

A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.50 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227000.

CVE-2022-32170
bytebase Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.

CVE-2022-4124
Popup Manager Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them

CVE-2022-38756
Micro Focus GroupWise Web Web
4.3
MEDIUM
EPSS
0.2%
2022 3 PoCs

A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies.

CVE-2022-2704
Simple E-Learning System Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-200 1 PoC

A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerability affects unknown code of the file downloadFiles.php. The manipulation of the argument download leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205828.

CVE-2022-4738
Blood Bank Management System Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

A vulnerability classified as problematic has been found in SourceCodester Blood Bank Management System 1.0. Affected is an unknown function of the file index.php?page=users of the component User Registration Handler. The manipulation of the argument Name leads to cross site scripting. It is possible to launch the attack remotely. VDB-216774 is the identifier assigned to this vulnerability.

CVE-2022-3585
Simple Cold Storage Management System Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-863 1 PoC

A vulnerability classified as problematic has been found in SourceCodester Simple Cold Storage Management System 1.0. Affected is an unknown function of the file /csms/?page=contact_us of the component Contact Us. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-211194 is the identifier assigned to this vulnerability.

CVE-2022-3245
microweber/microweber Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-94 1 PoC

HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.

CVE-2022-4103
Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets) Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title

CVE-2022-35611
Software Genérico Web
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

A Cross-Site Request Forgery (CSRF) in MQTTRoute v3.3 and below allows attackers to create and remove dashboards.