5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4103
Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets) Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title

CVE-2022-33930
Wyse Management Suite General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-209 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit this vulnerability, leading to the disclosure of certain sensitive information. The attacker may be able to use the exposed information to access and further vulnerability research.

CVE-2022-35611
Software Genérico Web
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

A Cross-Site Request Forgery (CSRF) in MQTTRoute v3.3 and below allows attackers to create and remove dashboards.

CVE-2022-3816
Bento4 General
4.3
MEDIUM
EPSS
0.5%
2022 CWE-404 1 PoC

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. The manipulation leads to memory leak. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212682 is the identifier assigned to this vulnerability.

CVE-2022-0226
livehelperchat/livehelperchat Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2022-4426
Mautic Integration for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

CVE-2022-41413
Software Genérico Web
4.3
MEDIUM
EPSS
1.5%
2022 3 PoCs

perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into the Search function.

CVE-2022-41297
Db2U Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212.

CVE-2022-22108
DaybydayCRM General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view this kind of information.

CVE-2022-2387
Easy Digital Downloads – Simple eCommerce for Selling Digital Files Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack

CVE-2022-3994
Authenticator Web Windows
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, which may deny other users access to the functionality in certain configurations.

CVE-2022-3812
Bento4 DevOps
4.3
MEDIUM
EPSS
0.3%
2022 CWE-404 1 PoC

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212678 is the identifier assigned to this vulnerability.

CVE-2022-4335
GitLab DevOps
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

CVE-2022-3292
ikus060/rdiffweb General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-524 1 PoC

Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-3151
WP Custom Cursors Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.

CVE-2022-21523
BI Publisher (formerly XML Publisher) Web Database
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2022-2912
Craw Data Web Windows
4.3
MEDIUM
EPSS
0.4%
2022 CWE-918 1 PoC

The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logged in admin change the url value performing unwanted crawls on third-party sites (SSRF).

CVE-2022-39887
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.

CVE-2022-2252
microweber/microweber General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.

CVE-2022-0510
pimcore/pimcore Web
4.3
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Packagist pimcore/pimcore prior to 10.3.1.