5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3451
Product Stock Manager Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options

CVE-2022-32205
https://github.com/curl/curl Web
4.3
MEDIUM
EPSS
2.6%
2022 CWE-770 1 PoC

A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to avoid sending crazy large requests (1048576 bytes) and instead returns an error.This denial state might remain for as long as the same cookies are kept, match and haven't expired. Due to cookie matching rules, a server on `foo.example.com` can set coo

CVE-2022-41313
SDS-3008 Series Industrial Ethernet Switch Web
4.3
MEDIUM
EPSS
2.3%
2022 CWE-79 2 PoCs

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="switch_contact"

CVE-2022-1417
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobs

CVE-2022-39873
Samsung Internet General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user authentication.

CVE-2022-3942
Sanitization Management System Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-707 2 PoCs

A vulnerability was found in SourceCodester Sanitization Management System and classified as problematic. This issue affects some unknown processing of the file php-sms/?p=request_quote. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-213449 was assigned to this vulnerability.

CVE-2022-1081
Microfinance Management System Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been declared as problematic. This vulnerability affects the file /mims/app/addcustomerHandler.php. The manipulation of the argument first_name, middle_name, and surname leads to cross site scripting. The attack can be initiated remotely.

CVE-2022-1004
OTRS General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled.

CVE-2022-30543
InRouter302 Networking
4.3
MEDIUM
EPSS
0.6%
2022 CWE-489 1 PoC

A leftover debug code vulnerability exists in the console infct functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to execution of privileged operations. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-33924
Wyse Management Suite General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with no access to create rules could potentially exploit this vulnerability and create rules.

CVE-2022-32170
bytebase Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.

CVE-2022-20713
Cisco Adaptive Security Appliance (ASA) Software Networking
4.3
MEDIUM
EPSS
1.7%
2022 CWE-444 3 PoCs

A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device. This vulnerability is due to improper validation of input that is passed to the VPN web client services component before being returned to the browser that is in use. An attacker could exploit this vulnerability by persuading a user to visit a website that is designed to pass malicious requests to a device that is running

CVE-2022-0708
Mattermost Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-200 1 PoC

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

CVE-2022-2913
Login No Captcha reCAPTCHA Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.

CVE-2022-0763
microweber/microweber Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-4148
WP OAuth Server (OAuth Authentication) Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.

CVE-2022-29915
Firefox Web
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.

CVE-2022-0282
microweber/microweber Web
4.3
MEDIUM
EPSS
0.7%
2022 CWE-79 1 PoC

Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-3017
froxlor/froxlor Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.

CVE-2022-2406
Mattermost Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-400 1 PoC

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.