5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22762
Firefox Web
4.3
MEDIUM
EPSS
0.3%
2022 2 PoCs

Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This could have been abused to trick the user. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVE-2022-4354
pb-cms Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-707 1 PoC

A vulnerability was found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /blog/comment of the component Message Board. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-215114 is the identifier assigned to this vulnerability.

CVE-2022-4549
Tickera Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVE-2022-3126
Frontend File Manager Plugin Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf

CVE-2022-3894
WP OAuth Server (OAuth Authentication) Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.

CVE-2022-0373
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVE-2022-36771
QRadar User Behavior Analytics General
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-Force ID: 232791.

CVE-2022-1074
FLEX-1085 General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-74 1 PoC

A vulnerability has been found in TEM FLEX-1085 1.6.0 and classified as problematic. Using the input <h1>HTML Injection</h1> in the WiFi settings of the dashboard leads to html injection.

CVE-2022-43753
SUSE Linux Enterprise Module for SUSE Manager Server 4.2 Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-22 1 PoC

A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2, SUSE Linux Enterprise Module for SUSE Manager Server 4.3, SUSE Manager Server 4.2 allows remote attackers to read files available to the user running the process, typically tomcat. This issue affects: SUSE Linux Enterprise Module for SUSE Manager Server 4.2 hub-xmlrpc-api-0.7-150300.3.9.2, inter-server-sync-0.2.4-150300.8.25.2, locale-formula-0.3-150300.3.3.2, py27-compat-salt-3000.3-150300.7.7.26.2, python-urlgrabber-3.1

CVE-2022-25783
GateManager General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-778 1 PoC

Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7.

CVE-2022-4014
FeehiCMS Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-863 1 PoC

A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The identifier of this vulnerability is VDB-213788.

CVE-2022-47130
Software Genérico Web
4.3
MEDIUM
EPSS
3.1%
2022 4 PoCs

A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page.

CVE-2022-48309
Sophos Connect Client Web
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.

CVE-2022-4770
Pentaho Business Analytics Server Database
4.3
MEDIUM
EPSS
0.4%
2022 CWE-209 1 PoC

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt). 

CVE-2022-2405
WP Popup Builder – Popup Forms , Marketing PoPuP & Newsletter Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup

CVE-2022-4246
PotPlayer General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-404 1 PoC

A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the component MID File Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214623.

CVE-2022-42129
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.

CVE-2022-20846
Cisco IOS XR Software Networking
4.3
MEDIUM
EPSS
2.0%
2022 CWE-120 1 PoC

A vulnerability in the Cisco&nbsp;Discovery Protocol implementation for Cisco&nbsp;IOS XR Software could allow an unauthenticated, adjacent attacker to cause the Cisco&nbsp;Discovery Protocol process to reload on an affected device. This vulnerability is due to a heap buffer overflow in certain Cisco&nbsp;Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco&nbsp;Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a heap overflow, which could cause the Cisco&nbsp;Discovery Protocol process to

CVE-2022-41263
Business Objects Business Intelligence Platform (Web intelligence) General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that is otherwise restricted. On successful exploitation, the attacker can modify information causing a limited impact on the integrity of the application.

CVE-2022-3817
Bento4 General
4.3
MEDIUM
EPSS
0.5%
2022 CWE-404 1 PoC

A vulnerability has been found in Axiomatic Bento4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component mp4mux. The manipulation leads to memory leak. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212683.