7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3942
Sanitization Management System Web
4.3
MEDIUM
EPSS
0.3%
2022 CWE-707 2 PoCs

A vulnerability was found in SourceCodester Sanitization Management System and classified as problematic. This issue affects some unknown processing of the file php-sms/?p=request_quote. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-213449 was assigned to this vulnerability.

CVE-2022-36771
QRadar User Behavior Analytics General
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-Force ID: 232791.

CVE-2022-0746
dolibarr/dolibarr General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.

CVE-2022-0273
janeczku/calibre-web General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper Access Control in Pypi calibreweb prior to 0.6.16.

CVE-2022-1074
FLEX-1085 General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-74 1 PoC

A vulnerability has been found in TEM FLEX-1085 1.6.0 and classified as problematic. Using the input <h1>HTML Injection</h1> in the WiFi settings of the dashboard leads to html injection.

CVE-2022-43753
SUSE Linux Enterprise Module for SUSE Manager Server 4.2 Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-22 1 PoC

A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2, SUSE Linux Enterprise Module for SUSE Manager Server 4.3, SUSE Manager Server 4.2 allows remote attackers to read files available to the user running the process, typically tomcat. This issue affects: SUSE Linux Enterprise Module for SUSE Manager Server 4.2 hub-xmlrpc-api-0.7-150300.3.9.2, inter-server-sync-0.2.4-150300.8.25.2, locale-formula-0.3-150300.3.3.2, py27-compat-salt-3000.3-150300.7.7.26.2, python-urlgrabber-3.1

CVE-2022-1081
Microfinance Management System Web
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been declared as problematic. This vulnerability affects the file /mims/app/addcustomerHandler.php. The manipulation of the argument first_name, middle_name, and surname leads to cross site scripting. The attack can be initiated remotely.

CVE-2022-25783
GateManager General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-778 1 PoC

Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries without logging. This issue affects: Secomea GateManager versions prior to 9.7.

CVE-2022-21592
MySQL Server Database
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.7.39 and prior and 8.0.29 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2022-39891
Editor Lite General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-125 1 PoC

Heap overflow vulnerability in parse_pce function in libsavsaudio.so in Editor Lite prior to version 4.0.41.3 allows attacker to get information.

CVE-2022-4014
FeehiCMS Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-863 1 PoC

A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The identifier of this vulnerability is VDB-213788.

CVE-2022-4944
KodExplorer Web
4.3
MEDIUM
EPSS
2.3%
2022 CWE-352 4 PoCs

A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.50 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227000.

CVE-2022-1332
Mattermost Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.

CVE-2022-1416
GitLab DevOps
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVE-2022-47130
Software Genérico Web
4.3
MEDIUM
EPSS
3.1%
2022 4 PoCs

A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page.

CVE-2022-48309
Sophos Connect Client Web
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.

CVE-2022-4349
pwn Web
4.3
MEDIUM
EPSS
0.1%
2022 CWE-863 1 PoC

A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215109 was assigned to this vulnerability.

CVE-2022-1004
OTRS General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled.

CVE-2022-21245
MySQL Server Database
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).

CVE-2022-1337
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-400 1 PoC

The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.