CVE-2022-0 to CVE-2022-999
536 CVEs with public proof-of-concept exploits.
- CVE-2022-00012 PoCsNon-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to…
- CVE-2022-00202 PoCsCortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web Interface
- CVE-2022-00701 PoCLog4j hot patch package privilege escalation
- CVE-2022-00711 PoCHotdog Container Escape
- CVE-2022-00791 PoCGeneration of Error Message Containing Sensitive Information in star7th/showdoc
- CVE-2022-00801 PoCHeap-based Buffer Overflow in mruby/mruby
- CVE-2022-00832 PoCsGeneration of Error Message Containing Sensitive Information in livehelperchat/livehelperchat
- CVE-2022-00851 PoCServer-Side Request Forgery (SSRF) in dompdf/dompdf
- CVE-2022-00861 PoCServer-Side Request Forgery (SSRF) in transloadit/uppy
- CVE-2022-00872 PoCsCross-site Scripting (XSS) - Reflected in keystonejs/keystone
- CVE-2022-00882 PoCsCross-Site Request Forgery (CSRF) in yourls/yourls
- CVE-2022-01211 PoCCross-site Scripting in hoppscotch/hoppscotch
- CVE-2022-01221 PoCOpen Redirect in digitalbazaar/forge
- CVE-2022-01281 PoCOut-of-bounds Read in vim/vim
- CVE-2022-01321 PoCServer-Side Request Forgery (SSRF) in chocobozzz/peertube
- CVE-2022-01331 PoCImproper Access Control in chocobozzz/peertube
- CVE-2022-01341 PoCAnyComment < 0.2.18 - Arbitrary HyperComments Import/Revert via CSRF
- CVE-2022-01371 PoCA heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries.
- CVE-2022-01391 PoCUse After Free in radareorg/radare2
- CVE-2022-01402 PoCsVisual Form Builder < 3.0.6 - Unauthenticated Information Disclosure
- CVE-2022-01421 PoCVisual Form Builder < 3.0.6 - CSV Injection
- CVE-2022-01441 PoCImproper Privilege Management in shelljs/shelljs
- CVE-2022-01451 PoCCross-site Scripting (XSS) - Stored in forkcms/forkcms
- CVE-2022-01472 PoCsCookie Information < 2.0.8 - Reflected Cross-Site Scripting
- CVE-2022-01482 PoCsAll-in-one Floating Contact Form < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2022-01492 PoCsWooCommerce – Store Exporter < 2.7.1 - Reflected Cross-Site Scripting (XSS)
- CVE-2022-01502 PoCsWP Accessibility Helper (WAH) < 0.6.0.7 - Reflected Cross-Site Scripting (XSS)
- CVE-2022-01531 PoCSQL Injection in forkcms/forkcms
- CVE-2022-01551 PoCExposure of Private Personal Information to an Unauthorized Actor in follow-redirects/follow-redirects
- CVE-2022-01561 PoCUse After Free in vim/vim
- CVE-2022-01571 PoCCross-site Scripting (XSS) - Stored in phoronix-test-suite/phoronix-test-suite
- CVE-2022-01581 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-01591 PoCCross-site Scripting (XSS) - Stored in orchardcms/orchardcore
- CVE-2022-01611 PoCARI Fancy Lightbox < 1.3.9 - Reflected Cross-Site Scripting
- CVE-2022-01631 PoCSmart Forms < 2.6.71 - Subscriber+ Form Data Download
- CVE-2022-01641 PoCComing soon and Maintenance mode < 3.6.7 - Subscriber+ Arbitrary Email Sending to Subscribed Users
- CVE-2022-01654 PoCsPage Builder KingComposer <= 2.9.6 - Open Redirect
- CVE-2022-01694 PoCsPhoto Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection
- CVE-2022-01731 PoCOut-of-bounds Read in radareorg/radare2
- CVE-2022-01741 PoCImproper Validation of Specified Quantity in Input in dolibarr/dolibarr
- CVE-2022-01761 PoCPowerPack Lite for Beaver Builder < 1.2.9.3 - Reflected Cross-Site Scripting
- CVE-2022-01781 PoCMissing Authorization in snipe/snipe-it
- CVE-2022-01791 PoCMissing Authorization in snipe/snipe-it
- CVE-2022-018511 PoCsKEVA heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the…
- CVE-2022-01861 PoCImage Photo Gallery Final Tiles Grid < 3.5.3 - Contributor+ Stored Cross-Site Scripting
- CVE-2022-01882 PoCsComing Soon & Maintenance Plugin by NiteoThemes < 4.0.19 - Unauthenticated Arbitrary CSS Update
- CVE-2022-01892 PoCsWP RSS Aggregator < 4.20 - Reflected Cross-Site Scripting (XSS)
- CVE-2022-01901 PoCAd Invalid Click Protector (AICP) < 1.2.6 - Authenticated SQL Injection
- CVE-2022-01911 PoCAd Invalid Click Protector (AICP) < 1.2.7 - Arbitrary Ban Deletion via CSRF
- CVE-2022-01931 PoCComplianz - GDPR/CCPA Cookie Consent < 6.0.0 - Reflected Cross-Site Scripting
- CVE-2022-01961 PoCCross-Site Request Forgery (CSRF) in phoronix-test-suite/phoronix-test-suite
- CVE-2022-01971 PoCCross-Site Request Forgery (CSRF) in phoronix-test-suite/phoronix-test-suite
- CVE-2022-01981 PoCImproper Restriction of XML External Entity Reference in stanfordnlp/corenlp
- CVE-2022-01991 PoCComing soon and Maintenance mode < 3.6.8 - Arbitrary Email Sending to Subscribed Users via CSRF
- CVE-2022-02001 PoCThemify Portfolio Post < 1.1.7 - Reflected Cross-Site Scripting
- CVE-2022-02012 PoCsPermalink Manager < 2.2.15 - Reflected Cross-Site Scripting
- CVE-2022-02031 PoCImproper Access Control in crater-invoice/crater
- CVE-2022-02041 PoCA heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially…
- CVE-2022-02051 PoCYOP Poll < 6.3.5 - Author+ Stored Cross-Site Scripting
- CVE-2022-02062 PoCsNewStatPress < 1.3.6 - Reflected Cross-Site Scripting
- CVE-2022-02082 PoCsMapPress Maps for WordPress < 2.73.4 - Reflected Cross-Site scripting
- CVE-2022-02111 PoCShield Security < 13.0.6 - Admin+ Stored Cross-Site Scripting
- CVE-2022-02122 PoCsSpiderCalendar <= 1.5.65 - Reflected Cross-Site Scripting
- CVE-2022-02131 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-02141 PoCPopup | Custom Popup Builder < 1.3.1 - Unauthenticated Denial of Service
- CVE-2022-02161 PoCA use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing…
- CVE-2022-02171 PoCIt was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in…
- CVE-2022-02181 PoCWP HTML Mail <= 3.0.9 Missing Authorization on REST-API Route
- CVE-2022-02193 PoCsImproper Restriction of XML External Entity Reference in skylot/jadx
- CVE-2022-02202 PoCsWordPress GDPR & CCPA < 1.9.27 - Unauthenticated Reflected Cross-Site Scripting
- CVE-2022-02241 PoCSQL Injection in dolibarr/dolibarr
- CVE-2022-02261 PoCCross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
- CVE-2022-02282 PoCsPopup Builder < 4.0.7 - Admin+ SQL Injection
- CVE-2022-02291 PoCminiOrange's Google Authenticator < 5.5 - Unauthenticated Arbitrary Options Deletion
- CVE-2022-02301 PoCBetter WordPress Google XML Sitemaps <= 1.4.1 - Unauthenticated Stored Cross-Site Scripting
- CVE-2022-02311 PoCCross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
- CVE-2022-02342 PoCsWOOCS < 1.3.7.5 - Reflected Cross-Site Scripting
- CVE-2022-02361 PoCWP Import Export (Lite) <= 3.9.15 Unauthenticated Sensitive Data Disclosure
- CVE-2022-02381 PoCCross-Site Request Forgery (CSRF) in phoronix-test-suite/phoronix-test-suite
- CVE-2022-02391 PoCImproper Restriction of XML External Entity Reference in stanfordnlp/corenlp
- CVE-2022-02401 PoCNULL Pointer Dereference in mruby/mruby
- CVE-2022-02421 PoCUnrestricted Upload of File with Dangerous Type in crater-invoice/crater
- CVE-2022-02431 PoCCross-site Scripting (XSS) - Stored in orchardcms/orchardcore
- CVE-2022-02451 PoCCross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
- CVE-2022-02461 PoCiQ Block Country < 1.2.13 - Admin+ Arbitrary File Deletion via Zip Slip
- CVE-2022-02481 PoCContact Form Submissions < 1.7.3 - Unauthenticated Stored XSS
- CVE-2022-02502 PoCsRedirection for Contact Form 7 < 2.5.0 - Reflected Cross-Site Scripting
- CVE-2022-02521 PoCGive < 2.17.3 - Reflected Cross-Site Scripting via Import Tool
- CVE-2022-02531 PoCCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
- CVE-2022-02541 PoCZero Spam < 5.2.11 - Admin+ SQL Injection
- CVE-2022-02551 PoCDatabase Backup for WordPress < 2.5.1 - Admin+ SQL Injection
- CVE-2022-02561 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-02571 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-02581 PoCSQL Injection in pimcore/pimcore
- CVE-2022-02611 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-02621 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-02631 PoCUnrestricted Upload of File with Dangerous Type in pimcore/pimcore
- CVE-2022-02652 PoCsImproper Restriction of XML External Entity Reference in hazelcast/hazelcast
- CVE-2022-02671 PoCAdRotate < 5.8.22 - Admin+ SQL Injection
- CVE-2022-02681 PoCCross-site Scripting (XSS) - Stored in getgrav/grav
- CVE-2022-02691 PoCCross-Site Request Forgery (CSRF) in yetiforcecompany/yetiforcecrm
- CVE-2022-02712 PoCsLearnPress < 4.1.6 - Reflected Cross-Site Scripting
- CVE-2022-02721 PoCImproper Restriction of XML External Entity Reference in detekt/detekt
- CVE-2022-02731 PoCImproper Access Control in janeczku/calibre-web
- CVE-2022-02741 PoCCross-site Scripting (XSS) - Stored in orchardcms/orchardcore
- CVE-2022-02771 PoCIncorrect Permission Assignment for Critical Resource in microweber/microweber
- CVE-2022-02781 PoCCross-site Scripting (XSS) - Stored in microweber/microweber
- CVE-2022-02791 PoCAnyComment < 0.2.18 - Comment Rating Increase/Decrease via Race Condition
- CVE-2022-02812 PoCsExposure of Sensitive Information to an Unauthorized Actor in microweber/microweber
- CVE-2022-02821 PoCCross-site Scripting in microweber/microweber
- CVE-2022-02841 PoCA heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is…
- CVE-2022-02851 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-02861 PoCA flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of service.
- CVE-2022-02871 PoCMycred < 2.4.4.1 - Subscriber+ User E-mail Addresses Disclosure
- CVE-2022-02882 PoCsAd Inserter < 2.7.10 - Reflected Cross-Site Scripting
- CVE-2022-03131 PoCFloat Menu < 4.3.1 - Arbitrary Menu Deletion via CSRF
- CVE-2022-03141 PoCNimble Page Builder < 3.2.2 - Reflected Cross-Site Scripting
- CVE-2022-03162 PoCsMultiple themes - Unauthenticated Arbitrary File Upload
- CVE-2022-03181 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-03191 PoCOut-of-bounds Read in vim/vim
- CVE-2022-03211 PoCWP Voting Contest < 3.0 - Reflected Cross-Site Scripting
- CVE-2022-03231 PoCImproper Neutralization of Special Elements Used in a Template Engine in bobthecow/mustache.php
- CVE-2022-03241 PoCBuffer Overflow in Dhcp6relay in Software for Open Networking in the Cloud (SONiC)
- CVE-2022-03261 PoCNULL Pointer Dereference in mruby/mruby
- CVE-2022-03271 PoCMaster Addons for Elementor < 1.8.2 - Reflected Cross-Site Scripting
- CVE-2022-03281 PoCSimple Membership < 4.0.9 - Arbitrary Member Deletion via CSRF
- CVE-2022-03323 PoCsA flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible…
- CVE-2022-03373 PoCsInappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attacker to obtain…
- CVE-2022-03391 PoCServer-Side Request Forgery (SSRF) in janeczku/calibre-web
- CVE-2022-03411 PoCCross-site Scripting (XSS) - Stored in vanessa219/vditor
- CVE-2022-03422 PoCsAn authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series…
- CVE-2022-03451 PoCBetter Notifications for WP < 1.8.7 - Email Address Disclosure
- CVE-2022-03462 PoCsGoogle XML Sitemap Generator < 2.0.4 - Reflected Cross-Site Scripting
- CVE-2022-03471 PoCLoginPress < 1.5.12 - Reflected Cross-Site Scripting
- CVE-2022-03481 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-03492 PoCsNotificationX < 2.3.9 - Unauthenticated Blind SQL Injection
- CVE-2022-03501 PoCCross-site Scripting (XSS) - Stored in vanessa219/vditor
- CVE-2022-03511 PoCAccess of Memory Location Before Start of Buffer in vim/vim
- CVE-2022-03521 PoCCross-site Scripting (XSS) - Reflected in janeczku/calibre-web
- CVE-2022-03591 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-03601 PoCWP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-03611 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-03621 PoCSQL Injection in star7th/showdoc
- CVE-2022-03631 PoCmyCred < 2.4.4 - Subscriber+ Arbitrary Post Creation
- CVE-2022-03641 PoCModern Events Calendar Lite < 6.4.0 - Contributor+ Stored Cross Site Scripting
- CVE-2022-03671 PoCA heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
- CVE-2022-03681 PoCOut-of-bounds Read in vim/vim
- CVE-2022-03701 PoCCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
- CVE-2022-03722 PoCsCross-site Scripting (XSS) - Stored in crater-invoice/crater
- CVE-2022-03741 PoCCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
- CVE-2022-03761 PoCUser Meta < 2.4.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-03772 PoCsLearnPress < 4.1.5 - Arbitrary Image Renaming
- CVE-2022-03782 PoCsCross-site Scripting (XSS) - Reflected in microweber/microweber
- CVE-2022-03791 PoCCross-site Scripting (XSS) - Stored in microweber/microweber
- CVE-2022-03812 PoCsEmbed Swagger <= 1.0.0 Reflected Cross-Site Scripting
- CVE-2022-03831 PoCWP Review Slider < 11.0 - Admin+ SQL Injection
- CVE-2022-03841 PoCVideo Conferencing with Zoom < 3.8.17 - E-mail Address Disclosure
- CVE-2022-03851 PoCCrazy Bone <= 0.6.0 - Unauthenticated Stored XSS
- CVE-2022-03871 PoCCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
- CVE-2022-03881 PoCInteractive Medical Drawing of Human Body < 2.6 - Admin+ Stored XSS
- CVE-2022-03891 PoCWP Time Slots Booking Form < 1.1.63 - Admin+ Stored Cross-Site Scripting
- CVE-2022-03921 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-03931 PoCOut-of-bounds Read in vim/vim
- CVE-2022-03941 PoCCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
- CVE-2022-03971 PoCWPC Smart Wishlist for WooCommerce < 2.9.4 - Reflected Cross-Site Scripting
- CVE-2022-03981 PoCThirstyAffiliates Affiliate Link Manager < 3.10.5 - Subscriber+ Arbitrary Affiliate Links Creation
- CVE-2022-03991 PoCAdvanced Product Labels for WooCommerce < 1.2.3.7 - Reflected Cross-Site Scripting
- CVE-2022-04011 PoCPath Traversal in yuda-lyu/w-zip
- CVE-2022-04021 PoCSuperforms < 6.0.4 - Reflected Cross-Site Scripting
- CVE-2022-04032 PoCsLibrary File Manager < 5.2.3 - Subscriber+ Arbitrary File Creation/Upload/Deletion
- CVE-2022-04041 PoCMaterial Design for Contact Form 7 <= 2.6.4 - Subscriber+ Arbitrary Settings Update leading to DoS
- CVE-2022-04051 PoCImproper Access Control in janeczku/calibre-web
- CVE-2022-04061 PoCImproper Authorization in janeczku/calibre-web
- CVE-2022-04071 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-04081 PoCStack-based Buffer Overflow in vim/vim
- CVE-2022-04091 PoCUnrestricted Upload of File with Dangerous Type in star7th/showdoc
- CVE-2022-04101 PoCWP Visitor Statistics (Real Time Traffic) < 5.6 - Subscriber+ SQL Injection
- CVE-2022-04111 PoCAsgaros Forum < 2.0.0 - Subscriber+ Blind SQL Injection
- CVE-2022-04122 PoCsTI WooCommerce Wishlist < 1.40.1 - Unauthenticated Blind SQL Injection
- CVE-2022-04131 PoCUse After Free in vim/vim
- CVE-2022-04141 PoCImproper Validation of Specified Quantity in Input in dolibarr/dolibarr
- CVE-2022-04152 PoCsRemote Command Execution in uploading repository file in gogs/gogs
- CVE-2022-04171 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-04181 PoCEvent List < 0.8.8 - Admin+ Stored Cross-Site Scripting
- CVE-2022-04191 PoCNULL Pointer Dereference in radareorg/radare2
- CVE-2022-04201 PoCRegistrationMagic < 5.0.2.2 - Admin+ SQL Injection
- CVE-2022-04211 PoCFive Star Restaurant Reservations < 2.4.12 - Unauthenticated Arbitrary Payment Status Update to Stored XSS
- CVE-2022-04222 PoCsWhite Label MS < 2.2.9 - Reflected Cross-Site Scripting
- CVE-2022-04231 PoC3D FlipBook < 1.12.1 - Subscriber+ Stored Cross-Site Scripting
- CVE-2022-04242 PoCsPopup by Supsystic < 1.10.9 - Unauthenticated Subscriber Email Addresses Disclosure
- CVE-2022-04261 PoCProduct Feed PRO for WooCommerce < 11.2.3 - Reflected Cross-Site Scripting
- CVE-2022-04271 PoCMissing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to…
- CVE-2022-04281 PoCContent Egg < 5.3.0 - Reflected Cross-Site Scripting
- CVE-2022-04292 PoCsWP Cerber Security, Anti-spam & Malware Scan < 8.9.6 - Unauthenticated Stored Cross-Site Scripting
- CVE-2022-04301 PoCExposure of Sensitive Information to an Unauthorized Actor in httpie/httpie
- CVE-2022-04311 PoCGoogle Pagespeed Insights < 4.0.4 - Reflected Cross-Site Scripting
- CVE-2022-04322 PoCsPrototype Pollution in mastodon/mastodon
- CVE-2022-04343 PoCsPage Views Count < 2.4.15 - Unauthenticated SQL Injection
- CVE-2022-04353 PoCsA stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content…
- CVE-2022-04361 PoCPath Traversal in gruntjs/grunt
- CVE-2022-04372 PoCsCross-site Scripting (XSS) - DOM in karma-runner/karma
- CVE-2022-04393 PoCsEmail Subscribers & Newsletters < 5.3.2 - Subscriber+ Blind SQL injection
- CVE-2022-04401 PoCCatch Themes Demo Import < 2.1.1 - Admin+ Remote Code Execution
- CVE-2022-04419 PoCsMasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
- CVE-2022-04421 PoCUsersWP < 1.2.3.1 - Subscriber+ User Avatar Override
- CVE-2022-04431 PoCUse After Free in vim/vim
- CVE-2022-04441 PoCXCloner < 4.3.6 - Plugin Settings Reset
- CVE-2022-04451 PoCWordPress Real Cookie Banner < 2.14.2 - Settings Reset via CSRF
- CVE-2022-04471 PoCPost Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types
- CVE-2022-04482 PoCsCP Blocks < 1.0.15 - Admin+ Stored Cross-Site Scripting
- CVE-2022-04491 PoCFlexi - Guest Submit < 4.20 - Reflected Cross-Site Scripting
- CVE-2022-04501 PoCMenu Image, Icons made easy < 3.0.8 - Subscriber+ Stored Cross-Site Scripting
- CVE-2022-04711 PoCFavicon by RealFaviconGenerator < 1.3.23 - Reflected Cross-Site Scripting
- CVE-2022-04721 PoCUnrestricted Upload of File with Dangerous Type in jsdecena/laracom
- CVE-2022-04761 PoCDenial of Service in radareorg/radare2
- CVE-2022-04781 PoCEvent Manager for WooCommerce < 3.5.8 - Contributor+ SQL Injection
- CVE-2022-04792 PoCsPopup Builder < 4.1.1 - SQL Injection to Reflected Cross-Site Scripting
- CVE-2022-04811 PoCNULL Pointer Dereference in mruby/mruby
- CVE-2022-04826 PoCsExposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
- CVE-2022-04861 PoCPrivileged Command Injection Vulnerability in Fidelis Network and Deception
- CVE-2022-04871 PoCA use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel.…
- CVE-2022-04891 PoCAn issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the…
- CVE-2022-049210 PoCsKEVA vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under…
- CVE-2022-04931 PoCString Locator < 2.5.0 - Admin+ Arbitrary File Read
- CVE-2022-04961 PoCA vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an…
- CVE-2022-04971 PoCA vulnerbiility was found in Openscad, where a .scad file with no trailing newline could cause an out-of-bounds read during parsing of…
- CVE-2022-04991 PoCSermon Browser <= 0.45.22 - Arbitrary File Upload via CSRF
- CVE-2022-05031 PoCMultisite Content Copier/Updater < 2.1.2 - Reflected Cross-Site Scripting
- CVE-2022-05051 PoCCross-Site Request Forgery (CSRF) in microweber/microweber
- CVE-2022-05061 PoCCross-site Scripting (XSS) - Stored in microweber/microweber
- CVE-2022-05091 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-05101 PoCCross-site Scripting (XSS) - Reflected in pimcore/pimcore
- CVE-2022-05121 PoCAuthorization Bypass Through User-Controlled Key in unshiftio/url-parse
- CVE-2022-05141 PoCBusiness Logic Errors in crater-invoice/crater
- CVE-2022-05151 PoCCross-Site Request Forgery (CSRF) in crater-invoice/crater
- CVE-2022-05181 PoCHeap-based Buffer Overflow in radareorg/radare2
- CVE-2022-05191 PoCBuffer Access with Incorrect Length Value in radareorg/radare2
- CVE-2022-05201 PoCUse After Free in radareorg/radare2
- CVE-2022-05211 PoCAccess of Memory Location After End of Buffer in radareorg/radare2
- CVE-2022-05221 PoCAccess of Memory Location Before Start of Buffer in radareorg/radare2
- CVE-2022-05231 PoCUse After Free in radareorg/radare2
- CVE-2022-05241 PoCBusiness Logic Errors in publify/publify
- CVE-2022-05251 PoCOut-of-bounds Read in mruby/mruby
- CVE-2022-05261 PoCCross-site Scripting (XSS) - Stored in chatwoot/chatwoot
- CVE-2022-05292 PoCsA flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of…
- CVE-2022-05302 PoCsA flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of…
- CVE-2022-05311 PoCWPvivid Backup and Migration Plugin < 0.9.70 - Reflected Cross-Site Scripting
- CVE-2022-05332 PoCsDitty (formerly Ditty News Ticker) < 3.0.15 - Reflected Cross-Site Scripting (XSS)
- CVE-2022-05341 PoCA vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when…
- CVE-2022-05352 PoCsE2Pdf < 1.16.45 - Admin+ Stored Cross-Site Scripting (XSS)
- CVE-2022-05371 PoCMapPress Maps for WordPress < 2.73.13 - Admin+ File Upload to Remote Code Execution
- CVE-2022-05391 PoCCross-site Scripting (XSS) - Stored in ptrofimov/beanstalk_console
- CVE-2022-05403 PoCsA vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP…
- CVE-2022-05411 PoCFlo Launch < 2.4.1 - Missing Authentication Allow Full Site Takeover
- CVE-2022-05421 PoCCross-site Scripting (XSS) - DOM in chatwoot/chatwoot
- CVE-2022-054312 PoCsKEVIt was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox…
- CVE-2022-05541 PoCUse of Out-of-range Pointer Offset in vim/vim
- CVE-2022-05573 PoCsOS Command Injection in microweber/microweber
- CVE-2022-05581 PoCCross-site Scripting (XSS) - Stored in microweber/microweber
- CVE-2022-05591 PoCUse After Free in radareorg/radare2
- CVE-2022-05601 PoCOpen Redirect in microweber/microweber
- CVE-2022-05611 PoCNull source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from…
- CVE-2022-05621 PoCNull source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to…
- CVE-2022-05651 PoCCross-site Scripting in pimcore/pimcore
- CVE-2022-05701 PoCHeap-based Buffer Overflow in mruby/mruby
- CVE-2022-05711 PoCCross-site Scripting (XSS) - Reflected in phoronix-test-suite/phoronix-test-suite
- CVE-2022-05721 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-05741 PoCImproper Access Control in publify/publify
- CVE-2022-05751 PoCCross-site Scripting (XSS) - Stored in librenms/librenms
- CVE-2022-05761 PoCCross-site Scripting (XSS) - Generic in librenms/librenms
- CVE-2022-05781 PoCCode Injection in publify/publify
- CVE-2022-05791 PoCMissing Authorization in snipe/snipe-it
- CVE-2022-05801 PoCIncorrect Authorization in librenms/librenms
- CVE-2022-05831 PoCCrash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or…
- CVE-2022-05861 PoCInfinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or…
- CVE-2022-05871 PoCImproper Authorization in librenms/librenms
- CVE-2022-05881 PoCMissing Authorization in librenms/librenms
- CVE-2022-05891 PoCCross-site Scripting (XSS) - Stored in librenms/librenms
- CVE-2022-05901 PoCBulletProof Security < 5.8 - Admin+ Stored Cross-Site Scripting (XSS)
- CVE-2022-05912 PoCsFormcraft3 < 3.8.28 - Unauthenticated SSRF
- CVE-2022-05922 PoCsMapSVG < 6.2.20 - Unauthenticated SQLi
- CVE-2022-05931 PoCLogin with phone number < 1.3.7 - Unauthenticated remote plugin deletion
- CVE-2022-05942 PoCsShareaholic < 9.7.6 - Information Disclosure
- CVE-2022-05952 PoCsDrag and Drop Multiple File Upload - Contact Form 7 < 1.3.6.3 - Unauthenticated Stored XSS
- CVE-2022-05961 PoCImproper Validation of Specified Quantity in Input in microweber/microweber
- CVE-2022-05972 PoCsOpen Redirect in microweber/microweber
- CVE-2022-05981 PoCLogin with phone number < 1.3.8 - Multiple Admin+ Stored XSS
- CVE-2022-05992 PoCsMapping Multiple URLs Redirect Same Page <= 5.8 - Reflected Cross-Site Scripting
- CVE-2022-06001 PoCConference Scheduler < 2.4.3 - Reflected Cross-Site Scripting
- CVE-2022-06011 PoCCountdown & Clock < 2.2.9 - Reflected Cross-Site Scripting
- CVE-2022-06021 PoCCross-site Scripting (XSS) - DOM in tastyigniter/tastyigniter
- CVE-2022-06111 PoCMissing Authorization in snipe/snipe-it
- CVE-2022-06131 PoCAuthorization Bypass Through User-Controlled Key in medialize/uri.js
- CVE-2022-06141 PoCUse of Out-of-range Pointer Offset in mruby/mruby
- CVE-2022-06161 PoCAmelia < 1.0.46 - Arbitrary Customer Deletion via CSRF
- CVE-2022-06171 PoCA flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter…
- CVE-2022-06191 PoCDatabase Peek <= 1.2 - Reflected Cross-Site Scripting
- CVE-2022-06201 PoCDelete Old Orders <= 0.2 - Reflected Cross-Site Scripting
- CVE-2022-06211 PoCdTabs <= 1.4 - Reflected Cross-Site Scripting
- CVE-2022-06231 PoCOut-of-bounds Read in mruby/mruby
- CVE-2022-06241 PoCAuthorization Bypass Through User-Controlled Key in ionicabizau/parse-path
- CVE-2022-06251 PoCAdmin Menu Editor <= 1.0.4 - Reflected Cross-Site Scripting
- CVE-2022-06261 PoCAdvanced Admin Search < 1.1.6 - Reflected Cross-Site Scripting
- CVE-2022-06271 PoCAmelia < 1.0.46 - Reflected Cross-Site Scripting
- CVE-2022-06281 PoCAP Mega Menu < 3.0.8 - Reflected Cross-Site Scripting
- CVE-2022-06291 PoCStack-based Buffer Overflow in vim/vim
- CVE-2022-06301 PoCOut-of-bounds Read in mruby/mruby
- CVE-2022-06311 PoCHeap-based Buffer Overflow in mruby/mruby
- CVE-2022-06321 PoCNULL Pointer Dereference in mruby/mruby
- CVE-2022-06331 PoCUpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Download
- CVE-2022-06341 PoCThirstyAffiliates < 3.10.5 - Subscriber+ unauthorized image upload + CSRF
- CVE-2022-06391 PoCAuthorization Bypass Through User-Controlled Key in unshiftio/url-parse
- CVE-2022-06401 PoCAP Pricing Tables Lite < 1.1.5 - Reflected Cross-Site Scripting
- CVE-2022-06411 PoCPopup Like box < 3.6.1 - Reflected Cross-Site Scripting
- CVE-2022-06421 PoCJivoChat < 1.3.5.4 - Stored Cross-Site Scripting via CSRF
- CVE-2022-06431 PoCBank Mellat <= 1.3.7 - Reflected Cross-Site Scripting
- CVE-2022-06451 PoCOpen redirect vulnerability via endpoint authorize_and_redirect/?redirect= in posthog/posthog
- CVE-2022-06471 PoCBulk Creator <= 1.0.1 - Reflected Cross-Site Scripting
- CVE-2022-06481 PoCTeam Circle Image Slider With Lightbox < 1.0.16 - Reflected Cross-Site Scripting
- CVE-2022-06491 PoCAdrotate < 5.8.23 - Admin+ XSS via Group Name
- CVE-2022-06512 PoCsWP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_type
- CVE-2022-06531 PoCProfile Builder – User Profile & User Registration Forms <= 3.6.1 Reflected Cross-Site Scripting
- CVE-2022-06541 PoCExposure of Sensitive Information to an Unauthorized Actor in fgribreau/node-request-retry
- CVE-2022-06563 PoCsuDraw < 3.3.3 - Unauthenticated Arbitrary File Access
- CVE-2022-06571 PoC5 Stars Rating Funnel < 1.2.53 - Unauthenticated SQLi
- CVE-2022-06582 PoCsCommonsBooking < 2.6.8 - Unauthenticated SQL Injection
- CVE-2022-06591 PoCSync iCloud COS < 2.0.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-06602 PoCsGeneration of Error Message Containing Sensitive Information in microweber/microweber
- CVE-2022-06611 PoCAd Injection <= 1.2.0.19 - Admin+ Stored Cross-Site Scripting & RCE
- CVE-2022-06621 PoCAdrotate < 5.8.23 - Admin+ XSS via Advert Name
- CVE-2022-06631 PoCPrint, PDF, Email by PrintFriendly < 5.2.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-06641 PoCUse of Hard-coded Cryptographic Key in gravitl/netmaker
- CVE-2022-06651 PoCPath Traversal in pimcore/pimcore
- CVE-2022-06662 PoCsCRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
- CVE-2022-06741 PoCKunze Law < 2.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-06761 PoCHeap-based Buffer Overflow in radareorg/radare2
- CVE-2022-06782 PoCsCross-site Scripting (XSS) - Reflected in microweber/microweber
- CVE-2022-06792 PoCsNarnoo Distributor <= 2.5.1 - Unauthenticated LFI to Arbitrary File Read / RCE
- CVE-2022-06801 PoCPlezi < 1.0.3 - Unauthenticated Stored XSS
- CVE-2022-06811 PoCSimple Membership < 4.1.0 - Arbitrary Transaction Deletion via CSRF
- CVE-2022-06841 PoCWP Home Page Menu < 3.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-06851 PoCUse of Out-of-range Pointer Offset in vim/vim
- CVE-2022-06861 PoCAuthorization Bypass Through User-Controlled Key in unshiftio/url-parse
- CVE-2022-06871 PoCAmelia < 1.0.46 - Manager+ RCE
- CVE-2022-06891 PoCUse multiple time the one-time coupon in microweber/microweber
- CVE-2022-06901 PoCCross-site Scripting (XSS) - Reflected in microweber/microweber
- CVE-2022-06911 PoCAuthorization Bypass Through User-Controlled Key in unshiftio/url-parse
- CVE-2022-06922 PoCsOpen Redirect on Rudloff/alltube in rudloff/alltube
- CVE-2022-06932 PoCsMaster Elements <= 8.0 - Unauthenticated SQLi
- CVE-2022-06941 PoCAdvanced Booking Calendar < 1.7.0 - Unauthenticated SQL Injection
- CVE-2022-06951 PoCDenial of Service in radareorg/radare2
- CVE-2022-06961 PoCNULL Pointer Dereference in vim/vim
- CVE-2022-06971 PoCOpen Redirect in archivy/archivy
- CVE-2022-07001 PoCSimple Theme Options < 1.7 - Admin+ Stored Cross-Site Scripting
- CVE-2022-07011 PoCSEO 301 Meta <= 1.9.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-07021 PoCPetfinder Listings <= 1.0.18 - Admin+ Stored Cross-Site Scripting
- CVE-2022-07031 PoCGD Mylist <= 1.1.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-07041 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-07051 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-07061 PoCEasy Digital Downloads < 2.11.6 - Admin+ Stored Cross-Site Scripting
- CVE-2022-07071 PoCEasy Digital Downloads < 2.11.6 - Arbitrary Payment Note Insertion via CSRF
- CVE-2022-07091 PoCBooking Package < 1.5.29 - Unauthenticated Sensitive Data Disclosure
- CVE-2022-07121 PoCNULL Pointer Dereference in radareorg/radare2
- CVE-2022-07131 PoCHeap-based Buffer Overflow in radareorg/radare2
- CVE-2022-07141 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-07171 PoCOut-of-bounds Read in mruby/mruby
- CVE-2022-07191 PoCCross-site Scripting (XSS) - Reflected in microweber/microweber
- CVE-2022-07201 PoCAmelia < 1.0.47 - Customer+ Arbitrary Appointments Update and Sensitive Data Disclosure
- CVE-2022-07211 PoCInsertion of Sensitive Information Into Debugging Code in microweber/microweber
- CVE-2022-07231 PoCCross-site Scripting (XSS) - Reflected in microweber/microweber
- CVE-2022-07241 PoCInsecure Storage of Sensitive Information in microweber/microweber
- CVE-2022-07251 PoCA flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information…
- CVE-2022-07261 PoCMissing Authorization in chocobozzz/peertube
- CVE-2022-07271 PoCImproper Access Control in chocobozzz/peertube
- CVE-2022-07281 PoCEasy Smooth Scroll Links < 2.23.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-07291 PoCUse of Out-of-range Pointer Offset in vim/vim
- CVE-2022-07311 PoCImproper Access Control (IDOR) in dolibarr/dolibarr
- CVE-2022-07351 PoCAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7…
- CVE-2022-07371 PoCText Hover < 4.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-073911 PoCsBookingPress < 1.0.11 - Unauthenticated SQL Injection
- CVE-2022-07431 PoCCross-site Scripting (XSS) - Stored in getgrav/grav
- CVE-2022-07451 PoCLike Button Rating < 2.6.45 - Arbitrary e-mail Sending
- CVE-2022-07461 PoCBusiness Logic Errors in dolibarr/dolibarr
- CVE-2022-07472 PoCsInfographic Maker - iList < 4.3.8 - Unauthenticated SQL Injection
- CVE-2022-07481 PoCArbitrary Code Execution
- CVE-2022-07492 PoCsDeserialization of Untrusted Data
- CVE-2022-07521 PoCCross-site Scripting (XSS) - Generic in hestiacp/hestiacp
- CVE-2022-07531 PoCCross-site Scripting (XSS) - Reflected in hestiacp/hestiacp
- CVE-2022-07541 PoCSQL Injection in salesagility/suitecrm
- CVE-2022-07551 PoCMissing Authorization in salesagility/suitecrm
- CVE-2022-07561 PoCMissing Authorization in salesagility/suitecrm
- CVE-2022-07602 PoCsSimple Link Directory < 7.7.2 - Unauthenticated SQL injection
- CVE-2022-07621 PoCIncorrect Authorization in microweber/microweber
- CVE-2022-07631 PoCCross-site Scripting (XSS) - Stored in microweber/microweber
- CVE-2022-07641 PoCArbitrary Command Injection in strapi/strapi
- CVE-2022-07652 PoCsLoco Translate < 2.6.1 - Authenticated Stored Cross-Site Scripting
- CVE-2022-07661 PoCServer-Side Request Forgery (SSRF) in janeczku/calibre-web
- CVE-2022-07671 PoCServer-Side Request Forgery (SSRF) in janeczku/calibre-web
- CVE-2022-07681 PoCServer-Side Request Forgery (SSRF) in rudloff/alltube
- CVE-2022-07692 PoCsUsers Ultra <= 3.1.0 - Unauthenticated SQL Injection
- CVE-2022-07701 PoCTranslate WordPress with GTranslate < 2.9.9 - CSRF to Account Takeover
- CVE-2022-07711 PoCSiteSuperCharger < 5.2.0 - Unauthenticated SQLi
- CVE-2022-07732 PoCsDocumentor <= 1.5.3 - Unauthenticated SQLi
- CVE-2022-07751 PoCWooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion
- CVE-2022-07762 PoCsCross-site Scripting (XSS) - DOM in hakimel/reveal.js
- CVE-2022-07771 PoCWeak Password Recovery Mechanism for Forgotten Password in microweber/microweber
- CVE-2022-07787 PoCsInfinite loop in BN_mod_sqrt() reachable when parsing certificates
- CVE-2022-07791 PoCUser Meta < 2.4.4 - Subscriber+ Local File Enumeration via Path Traversal
- CVE-2022-07801 PoCSearchIQ < 3.9 - Unauthenticated Stored XSS
- CVE-2022-07812 PoCsNirweb support < 2.8.2 - Unauthenticated SQLi
- CVE-2022-07821 PoCDonations <= 1.8 - Unauthenticated SQLi
- CVE-2022-07832 PoCsMultiple Shipping Address Woocommerce < 2.0 - Unauthenticated SQLi
- CVE-2022-07842 PoCsTitle Experiments Free < 9.0.1 - Unauthenticated SQLi
- CVE-2022-07852 PoCsDaily Prayer Time < 2022.03.01 - Unauthenticated SQLi
- CVE-2022-07862 PoCsKiviCare < 2.3.9 - Unauthenticated SQLi
- CVE-2022-07872 PoCsLimit Login Attempts (Spam Protection) < 5.1 - Unauthenticated SQLi
- CVE-2022-07882 PoCsWP Fundraising Donation and Crowdfunding Platform < 1.5.0 - Unauthenticated SQLi
- CVE-2022-08113 PoCsA flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes…
- CVE-2022-08142 PoCsUbigeo de Peru < 3.6.4 - Unauthenticated SQLi
- CVE-2022-08172 PoCsBadgeOS <= 3.7.0 - Unauthenticated SQLi
- CVE-2022-08181 PoCCoupon Affiliates < 4.16.4.5 - Unauthenticated Stored XSS
- CVE-2022-08191 PoCCode Injection in dolibarr/dolibarr
- CVE-2022-08211 PoCImproper Authorization in orchardcms/orchardcore
- CVE-2022-08221 PoCCross-site Scripting (XSS) - Reflected in orchardcms/orchardcore
- CVE-2022-082412 PoCsImproper Access Control to Remote Code Execution in webmin/webmin
- CVE-2022-08251 PoCAmelia < 1.0.49 - Customer+ Arbitrary Appointments Status Update
- CVE-2022-08262 PoCsWP Video Gallery <= 1.7.1 - Unauthenticated SQLi
- CVE-2022-08272 PoCsBestbooks <= 2.6.3 - Unauthenticated SQLi
- CVE-2022-08281 PoCDownload Manager < 3.2.39 - Unauthenticated brute force of files master key
- CVE-2022-08293 PoCsImproper Authorization in webmin/webmin
- CVE-2022-08301 PoCFormBuilder <= 1.08 - Stored Cross-Site Scripting via CSRF
- CVE-2022-08331 PoCChurch Admin < 3.4.135 - Unauthenticated Plugin's Backup Disclosure
- CVE-2022-08361 PoCSEMA API < 4.02 - Unauthenticated SQLi
- CVE-2022-08371 PoCAmelia < 1.0.48 - Customer+ SMS Service Abuse and Sensitive Data Disclosure
- CVE-2022-08381 PoCCross-site Scripting (XSS) - Reflected in hestiacp/hestiacp
- CVE-2022-08391 PoCImproper Restriction of XML External Entity Reference in liquibase/liquibase
- CVE-2022-08401 PoCEasy Social Icons < 3.2.1 - Admin+ Stored Cross-Site Scripting in add icon
- CVE-2022-08411 PoCOS Command Injection in ljharb/npm-lockfile
- CVE-2022-08451 PoCCode Injection in pytorchlightning/pytorch-lightning
- CVE-2022-08463 PoCsSpeakOut! Email Petitions < 2.14.15.1 - Unauthenticated SQLi
- CVE-2022-0847156 PoCsKEVA flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in…
- CVE-2022-08487 PoCsOS Command Injection in part-db/part-db
- CVE-2022-08491 PoCUse After Free in r_reg_get_name_idx in radareorg/radare2
- CVE-2022-08531 PoCA flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction…
- CVE-2022-08541 PoCA memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user…
- CVE-2022-08561 PoClibcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Service
- CVE-2022-08601 PoCImproper Authorization in cobbler/cobbler
- CVE-2022-08631 PoCWP SVG Icons <= 3.2.3 - Admin+ Remote Code Execution (RCE)
- CVE-2022-08643 PoCsUpdraftPlus < 1.22.9 - Reflected Cross-Site Scripting
- CVE-2022-08651 PoCReachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that…
- CVE-2022-08672 PoCsARPrice Lite < 3.6.1 - Unauthenticated SQLi
- CVE-2022-08681 PoCOpen Redirect in medialize/uri.js
- CVE-2022-08692 PoCsMultiple Open Redirect in nitely/spirit
- CVE-2022-08702 PoCsServer-Side Request Forgery (SSRF) in gogs/gogs
- CVE-2022-08711 PoCMissing Authorization in gogs/gogs
- CVE-2022-08732 PoCsGmedia Photo Gallery < 1.20.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-08741 PoCWP Social Buttons <= 2.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-08751 PoCminiOrange Google Authenticator < 1.0.5 - CSRF to Stored Cross-Site Scripting
- CVE-2022-08761 PoCSocial comments by WpDevArt < 2.5.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-08771 PoCCross-site Scripting (XSS) - Stored in bookstackapp/bookstack
- CVE-2022-08792 PoCsCaldera Forms < 1.9.7 - Reflected Cross-Site Scripting
- CVE-2022-08811 PoCInsecure Storage of Sensitive Information in chocobozzz/peertube
- CVE-2022-08841 PoCProfile Builder < 3.6.8 - Admin+ Stored Cross-Site Scripting
- CVE-2022-08852 PoCsMember Hero <= 1.0.9 - Unauthenticated RCE
- CVE-2022-08871 PoCEasy Social Icons < 3.1.4 - Admin+ SQL Injection
- CVE-2022-08881 PoCNinja Forms - File Uploads Extension <= 3.3.0 - Arbitrary File Upload
- CVE-2022-08901 PoCNULL Pointer Dereference in mruby/mruby
- CVE-2022-08912 PoCsA heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or…
- CVE-2022-08921 PoCExport All URLs < 4.2 - Reflected Cross-Site Scripting
- CVE-2022-08931 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-08941 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-08951 PoCStatic Code Injection in microweber/microweber
- CVE-2022-08961 PoCImproper Neutralization of Special Elements Used in a Template Engine in microweber/microweber
- CVE-2022-08981 PoCIgniteUp <= 3.4.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-08992 PoCsHeader Footer Code Manager < 1.1.24 - Reflected Cross-Site Scripting
- CVE-2022-09012 PoCsAd Inserter < 2.7.12 - Reflected Cross-Site Scripting
- CVE-2022-09051 PoCMissing Authorization in go-gitea/gitea
- CVE-2022-09061 PoCUnrestricted file upload leads to stored XSS in microweber/microweber
- CVE-2022-09071 PoCUnchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a…
- CVE-2022-09081 PoCNull source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to…
- CVE-2022-09091 PoCDivide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that…
- CVE-2022-09111 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-09121 PoCUnrestricted Upload of File with Dangerous Type in microweber/microweber
- CVE-2022-09131 PoCInteger Overflow or Wraparound in microweber/microweber
- CVE-2022-09141 PoCExport All URLs < 4.3 - Private/Draft Post/Page Title Disclosure via CSRF
- CVE-2022-09181 PoCA vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to…
- CVE-2022-09191 PoCSalon booking system < 7.6.3 - Unauthenticated Sensitive Data Disclosure
- CVE-2022-09201 PoCSalon booking system < 7.6.3 - Customer+ Bookings/Customers Data Disclosure
- CVE-2022-09212 PoCsAbusing Backup/Restore feature to achieve Remote Code Execution in microweber/microweber
- CVE-2022-09241 PoCOut-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that…
- CVE-2022-09261 PoCFile upload filter bypass leading to stored XSS in microweber/microweber
- CVE-2022-09282 PoCsCross-site Scripting (XSS) - Stored in microweber/microweber
- CVE-2022-09291 PoCXSS on dynamic_text module in microweber/microweber
- CVE-2022-09301 PoCFile upload filter bypass leading to stored XSS in microweber/microweber
- CVE-2022-09351 PoCHost Header injection in password Reset in livehelperchat/livehelperchat
- CVE-2022-09361 PoCCross-site Scripting (XSS) - Stored in autolab/autolab
- CVE-2022-09371 PoCStored xss in showdoc through file upload in star7th/showdoc
- CVE-2022-09381 PoCStored XSS via file upload in star7th/showdoc
- CVE-2022-09391 PoCServer-Side Request Forgery (SSRF) in janeczku/calibre-web
- CVE-2022-09401 PoCStored XSS due to Unrestricted File Upload in star7th/showdoc
- CVE-2022-09411 PoCStored XSS due to Unrestricted File Upload in star7th/showdoc
- CVE-2022-09421 PoCStored XSS due to Unrestricted File Upload in star7th/showdoc
- CVE-2022-09431 PoCHeap-based Buffer Overflow occurs in vim in vim/vim
- CVE-2022-094412 PoCsTemplate injection in connection test endpoint leads to RCE in sqlpad/sqlpad
- CVE-2022-09451 PoCStored XSS viva axd and cshtml file upload in star7th/showdoc in star7th/showdoc
- CVE-2022-09461 PoCStored XSS viva cshtm file upload in star7th/showdoc
- CVE-2022-09482 PoCsOrder Listener for WooCommerce < 3.2.2 - Unauthenticated SQLi
- CVE-2022-09492 PoCsWP Block and Stop Bad Bots < 6.930 - Unauthenticated SQLi
- CVE-2022-09501 PoCUnrestricted Upload of File with Dangerous Type in star7th/showdoc
- CVE-2022-09511 PoCFile Upload Restriction Bypass leading to Stored XSS Vulnerability in star7th/showdoc
- CVE-2022-09523 PoCsSitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update
- CVE-2022-09531 PoCAnti-Malware Security and Brute-Force Firewall < 4.20.96 - Reflected Cross-Site Scripting
- CVE-2022-09542 PoCsMultiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops'…
- CVE-2022-09551 PoCCross-site Scripting (XSS) - Stored in pimcore/data-hub
- CVE-2022-09561 PoCStored XSS via File Upload in star7th/showdoc
- CVE-2022-09571 PoCStored XSS via File Upload in star7th/showdoc
- CVE-2022-09581 PoCMark Posts < 2.0.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-09601 PoCStored XSS viva .properties file upload in star7th/showdoc
- CVE-2022-09611 PoCThe microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial…
- CVE-2022-09621 PoCStored XSS viva .webma file upload in star7th/showdoc
- CVE-2022-09632 PoCsUnrestricted XML Files Leads to Stored XSS in microweber/microweber
- CVE-2022-09641 PoCStored XSS viva .webmv file upload in star7th/showdoc
- CVE-2022-09651 PoCStored XSS viva .ofd file upload in star7th/showdoc
- CVE-2022-09661 PoCStored XSS via File Upload in star7th/showdoc in star7th/showdoc
- CVE-2022-09673 PoCsStored XSS via File Upload in star7th/showdoc in star7th/showdoc in star7th/showdoc
- CVE-2022-09682 PoCsThe microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a…
- CVE-2022-09691 PoCImage optimization & Lazy Load < 3.3.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-09701 PoCCross-site Scripting (XSS) - Stored in getgrav/grav
- CVE-2022-09861 PoCReflected Cross-site Scripting (XSS) Vulnerability in hestiacp/hestiacp
- CVE-2022-09891 PoCNS WooCommerce Watermark <= 2.11.3 - Abuse of Functionality
- CVE-2022-09901 PoCServer-Side Request Forgery (SSRF) in janeczku/calibre-web
- CVE-2022-09911 PoCInsufficient Session Expiration in admidio/admidio
- CVE-2022-09941 PoCHummingbird < 3.3.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-09957 PoCsKEVAn out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite…
- CVE-2022-09961 PoCA vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
- CVE-2022-09971 PoCLocal Privilege Escalation Vulnerability in Fidelis Network and Deception