5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3850
Find and Replace All Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack

CVE-2022-41312
SDS-3008 Series Industrial Ethernet Switch Web
4.3
MEDIUM
EPSS
1.1%
2022 CWE-79 2 PoCs

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="Switch Description", name "switch_description"

CVE-2022-2846
Calendar Event Multi View Web Windows
4.3
MEDIUM
EPSS
3.0%
2022 CWE-862 2 PoCs

The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.

CVE-2022-1102
Royale Event Management System Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-79 2 PoCs

A vulnerability classified as problematic has been found in SourceCodester Royale Event Management System 1.0. Affected is an unknown function of the file /royal_event/companyprofile.php. The manipulation of the argument companyname/regno/companyaddress/companyemail leads to cross site scripting. It is possible to launch the attack remotely. VDB-195786 is the identifier assigned to this vulnerability.

CVE-2022-2450
reSmush.it : the only free Image Optimizer & compress plugin Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.

CVE-2022-3098
Login Block IPs Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-32169
bytebase General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.

CVE-2022-1174
GitLab DevOps
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVE-2022-2408
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

CVE-2022-3301
ikus060/rdiffweb General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-460 1 PoC

Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-3336
Event Monster Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack

CVE-2022-0406
janeczku/calibre-web General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.

CVE-2022-4769
Pentaho Business Analytics Server General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-209 1 PoC

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name. 

CVE-2022-1760
Core Control Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Core Control WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-45634
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows authenticated attacker to gain access to sensitive account information

CVE-2022-3876
Passwordstate Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-266 2 PoCs

A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This issue affects some unknown processing of the file /api/browserextension/UpdatePassword/ of the component API. The manipulation of the argument PasswordID leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier VDB-216245 was assigned to this vulnerability.

CVE-2022-38482
Software Genérico General
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

A link-manipulation issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP4.

CVE-2022-25820
Samsung Mobile Devices General
4.2
MEDIUM
EPSS
0.0%
2022 CWE-307 1 PoC

A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.

CVE-2022-24932
Samsung Mobile Devices General
4.2
MEDIUM
EPSS
0.0%
2022 CWE-424 1 PoC

Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.

CVE-2022-24927
Samsung Video Player General
4.2
MEDIUM
EPSS
0.1%
2022 CWE-269 1 PoC

Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.