5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-20917
Cisco Jabber Networking
4.3
MEDIUM
EPSS
0.2%
2022 CWE-668 1 PoC

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to the improper handling of nested XMPP messages within requests that are sent to the Cisco Jabber client software. An attacker could exploit this vulnerability by connecting to an XMPP messaging server and sending crafted XMPP messages to an affected Jabber client. A successful exploit could allow the attacker to manipula

CVE-2022-4019
Playbooks Plugin Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-770 1 PoC

A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.

CVE-2022-21948
paste Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in paste allows remote attackers to place Javascript into SVG files. This issue affects: openSUSE paste paste version b57b9f87e303a3db9465776e657378e96845493b and prior versions.

CVE-2022-41311
SDS-3008 Series Industrial Ethernet Switch Web
4.3
MEDIUM
EPSS
1.1%
2022 CWE-79 2 PoCs

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="webLocationMessage_text" name="webLocationMessage_text"

CVE-2022-1079
One Church Management System General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability classified as problematic has been found in SourceCodester One Church Management System. Affected are multiple files and parameters which are prone to to cross site scripting. It is possible to launch the attack remotely.

CVE-2022-42067
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2022 2 PoCs

Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability

CVE-2022-0597
microweber/microweber General ⚡ nuclei
4.3
MEDIUM
EPSS
1.0%
2022 CWE-601 1 PoC

Open Redirect in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0746
dolibarr/dolibarr General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.

CVE-2022-0273
janeczku/calibre-web General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper Access Control in Pypi calibreweb prior to 0.6.16.

CVE-2022-21592
MySQL Server Database
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.7.39 and prior and 8.0.29 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2022-39891
Editor Lite General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-125 1 PoC

Heap overflow vulnerability in parse_pce function in libsavsaudio.so in Editor Lite prior to version 4.0.41.3 allows attacker to get information.

CVE-2022-1332
Mattermost Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.

CVE-2022-4349
pwn Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-863 1 PoC

A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215109 was assigned to this vulnerability.

CVE-2022-21245
MySQL Server Database
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).

CVE-2022-1337
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-400 1 PoC

The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.

CVE-2022-3173
snipe/snipe-it General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-287 1 PoC

Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.

CVE-2022-3282
Drag and Drop Multiple File Upload – Contact Form 7 Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.

CVE-2022-21383
Enterprise Session Border Controller Web Database
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Log). Supported versions that are affected are 8.4 and 9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Session Border Controller. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/

CVE-2022-3223
jgraph/drawio Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.

CVE-2022-27172
InRouter302 Networking
4.3
MEDIUM
EPSS
0.4%
2022 CWE-259 1 PoC

A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can send a sequence of requests to trigger this vulnerability.