7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-42126
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.

CVE-2022-3850
Find and Replace All Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack

CVE-2022-20713
Cisco Adaptive Security Appliance (ASA) Software Networking
4.3
MEDIUM
EPSS
1.7%
2022 CWE-444 3 PoCs

A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device. This vulnerability is due to improper validation of input that is passed to the VPN web client services component before being returned to the browser that is in use. An attacker could exploit this vulnerability by persuading a user to visit a website that is designed to pass malicious requests to a device that is running

CVE-2022-3138
jgraph/drawio Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.

CVE-2022-0708
Mattermost Web
4.3
MEDIUM
EPSS
0.4%
2022 CWE-200 1 PoC

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

CVE-2022-41312
SDS-3008 Series Industrial Ethernet Switch Web
4.3
MEDIUM
EPSS
1.1%
2022 CWE-79 2 PoCs

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="Switch Description", name "switch_description"

CVE-2022-28777
Samsung Members General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute call function without CALL_PHONE permission.

CVE-2022-3451
Product Stock Manager Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options

CVE-2022-0226
livehelperchat/livehelperchat Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2022-2460
WPDating Web Database Windows
4.3
MEDIUM
EPSS
4.4%
2022 1 PoC

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

CVE-2022-25839
url-js Web
4.3
MEDIUM
EPSS
0.2%
2022 3 PoCs

The package url-js before 2.1.0 are vulnerable to Improper Input Validation due to improper parsing, which makes it is possible for the hostname to be spoofed. http://\\\\\\\\localhost and http://localhost are the same URL. However, the hostname is not parsed as localhost, and the backslash is reflected as it is.

CVE-2022-4426
Mautic Integration for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

CVE-2022-4408
thorsten/phpmyfaq Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

CVE-2022-3030
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

CVE-2022-4280
Smart Campus System General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-266 1 PoC

A vulnerability, which was classified as problematic, has been found in Dot Tech Smart Campus System. Affected by this issue is some unknown functionality of the file /services/Card/findUser. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214778 is the identifier assigned to this vulnerability.

CVE-2022-42159
Software Genérico General
4.3
MEDIUM
EPSS
0.5%
2022 1 PoC

D-Link COVR 1200,1202,1203 v1.08 was discovered to have a predictable seed in a Pseudo-Random Number Generator.

CVE-2022-4872
Chained Products Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ensure that the option to be updated belong to the plugin, allowing unauthenticated attackers to set arbitrary options to 'no'

CVE-2022-3464
puppyCMS Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-707 2 PoCs

A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.

CVE-2022-4004
Donation Button Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone numbers.

CVE-2022-3233
ikus060/rdiffweb Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.