7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3812
Bento4 DevOps
4.3
MEDIUM
EPSS
0.3%
2022 CWE-404 1 PoC

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212678 is the identifier assigned to this vulnerability.

CVE-2022-0406
janeczku/calibre-web General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.

CVE-2022-3336
Event Monster Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack

CVE-2022-3301
ikus060/rdiffweb General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-460 1 PoC

Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-2408
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

CVE-2022-29915
Firefox Web
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.

CVE-2022-4335
GitLab DevOps
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

CVE-2022-3292
ikus060/rdiffweb General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-524 1 PoC

Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-3151
WP Custom Cursors Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.

CVE-2022-21523
BI Publisher (formerly XML Publisher) Web Database
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2022-4013
Hospital Management Center Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-863 1 PoC

A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an unknown functionality of the file appointment.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213787.

CVE-2022-0405
janeczku/calibre-web General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.

CVE-2022-37426
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.

CVE-2022-2912
Craw Data Web Windows
4.3
MEDIUM
EPSS
0.4%
2022 CWE-918 1 PoC

The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logged in admin change the url value performing unwanted crawls on third-party sites (SSRF).

CVE-2022-0282
microweber/microweber Web
4.3
MEDIUM
EPSS
0.7%
2022 CWE-79 1 PoC

Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-0906
microweber/microweber Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.

CVE-2022-0348
pimcore/pimcore Web
4.3
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.

CVE-2022-39887
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.

CVE-2022-3017
froxlor/froxlor Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.

CVE-2022-41313
SDS-3008 Series Industrial Ethernet Switch Web
4.3
MEDIUM
EPSS
2.3%
2022 CWE-79 2 PoCs

A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="switch_contact"