CVE-2022-1000 to CVE-2022-1999
531 CVEs with public proof-of-concept exploits.
- CVE-2022-10001 PoCPath Traversal in prasathmani/tinyfilemanager
- CVE-2022-10011 PoCWP Downgrade < 1.2.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10051 PoCWP Statistics < 13.2.2 - Reflected Cross-Site Scripting
- CVE-2022-10061 PoCAdvanced Booking Calendar < 1.7.1 - Admin+ SQLi
- CVE-2022-10072 PoCsAdvanced Booking Calendar < 1.7.1 - Reflected Cross-Site Scripting
- CVE-2022-10081 PoCOne Click Demo Import < 3.1.0 - Admin+ Arbitrary File Upload
- CVE-2022-10091 PoCSmush < 3.9.9 - Admin+ Reflected Cross-Site Scripting
- CVE-2022-10101 PoCLogin using WordPress Users < 1.13.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10111 PoCA use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to…
- CVE-2022-10132 PoCsPersonal Dictionary < 1.3.4 - Unauthenticated SQLi
- CVE-2022-10141 PoCWP Contacts Manager <= 2.2.4 - Unauthenticated SQLi
- CVE-2022-101514 PoCsA flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to…
- CVE-2022-10161 PoCA flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to…
- CVE-2022-10203 PoCsWoo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Call
- CVE-2022-10211 PoCInsecure Storage of Sensitive Information in chatwoot/chatwoot
- CVE-2022-10221 PoCCross-site Scripting (XSS) - Stored in chatwoot/chatwoot
- CVE-2022-10231 PoCPodcast Importer SecondLine < 1.3.8 - Admin+ SQLi
- CVE-2022-10268 PoCsKyocera Net View Address Book Exposure
- CVE-2022-10271 PoCPage Restriction WordPress < 1.2.7 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10281 PoCWordPress Security < 4.2.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10292 PoCsLimit Login Attempts < 4.0.72 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10311 PoCUse After Free in op_is_set_bp in radareorg/radare2
- CVE-2022-10321 PoCInsecure deserialization of not validated module file in crater-invoice/crater
- CVE-2022-10331 PoCUnrestricted Upload of File with Dangerous Type in crater-invoice/crater
- CVE-2022-10341 PoCThere is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in star7th/showdoc
- CVE-2022-10371 PoCEXMAGE < 1.0.7 - Admin+ Blind SSRF
- CVE-2022-104010 PoCsKEVAn authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version…
- CVE-2022-10432 PoCsA flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to corrupt system…
- CVE-2022-10441 PoCSensitive Data Exposure Due To Insecure Storage Of Profile Image in polonel/trudesk
- CVE-2022-10451 PoCStored XSS viva .svg file upload in polonel/trudesk
- CVE-2022-10461 PoCVisual Form Builder < 3.0.7 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10471 PoCThemify - Post Type Builder Search Addon < 1.4.0 - Reflected Cross-Site Scripting
- CVE-2022-10491 PoCA flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired…
- CVE-2022-10512 PoCsWPQA < 5.2 - Subscriber+ Stored Cross-Site Scripting via Profile fields
- CVE-2022-10521 PoCHeap Buffer Overflow in iterate_chained_fixups in radareorg/radare2
- CVE-2022-10542 PoCsRSVP and Event Management < 2.7.8 - Unauthenticated Entries Export
- CVE-2022-10561 PoCOut-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users…
- CVE-2022-10572 PoCsPricing Deals for WooCommerce <= 2.0.2.02 - Unauthenticated SQLi
- CVE-2022-10582 PoCsOpen Redirect on login in go-gitea/gitea
- CVE-2022-10611 PoCHeap Buffer Overflow in parseDragons in radareorg/radare2
- CVE-2022-10621 PoCth23 Social <= 1.2.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10631 PoCThank Me Later <= 3.3.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10641 PoCSQL injection through marking blog comments on bulk as spam in forkcms/forkcms
- CVE-2022-10651 PoCMulti Factor Authentication Bypass in various versions of Abacus ERP
- CVE-2022-10681 PoCModbus Tools Modbus Slave Stack-Based Buffer Overflow
- CVE-2022-10711 PoCUser after free in mrb_vm_exec in mruby/mruby
- CVE-2022-10772 PoCsTEM FLEX-1080/FLEX-1085 Log information disclosure
- CVE-2022-10861 PoCDolphinPHP User Management Page cross site scripting
- CVE-2022-10871 PoChtmly Edit Profile Module cross site scripting
- CVE-2022-10881 PoCPage Security & Membership <= 1.5.15 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10891 PoCBulk Edit and Create User Profiles < 1.5.14 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10901 PoCGood & Bad Comments <= 1.0.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10911 PoCSafe SVG < 1.9.10 - SVG Sanitisation Bypass
- CVE-2022-10921 PoCmyCred < 2.4.4 - Subscriber+ Import/Export to Email Address Disclosure
- CVE-2022-10931 PoCWP Meta SEO < 4.4.7 - Admin+ Stored Cross-Site Scripting via breadcrumbs
- CVE-2022-10941 PoCAmr Users < 4.59.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-10951 PoCMihdan: No External Links < 5.0.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-11032 PoCsAdvanced Uploader <= 4.2 - Subscriber+ Arbitrary File Upload
- CVE-2022-11042 PoCsPopup Maker < 1.16.5 - Admin+ Stored Cross-Site Scripting
- CVE-2022-11061 PoCuse after free in mrb_vm_exec in mruby/mruby
- CVE-2022-11121 PoCAutolinks <= 1.0.1 - Stored Cross-Site Scripting via CSRF
- CVE-2022-11131 PoCFlower Delivery by Florist One <= 3.7 - Admin+ Stored Cross-Site Scripting
- CVE-2022-11151 PoCA heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is…
- CVE-2022-11195 PoCsSimple File List <= 3.2.7 - Arbitrary File Download
- CVE-2022-11231 PoCLeaflet Maps Marker < 3.12.5 - Admin+ SQLi
- CVE-2022-11521 PoCMenubar < 5.8 - Reflected Cross-Site Scripting
- CVE-2022-11531 PoCLayerSlider < 7.1.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-11541 PoCUse after free in utf_ptr2char in vim/vim
- CVE-2022-11551 PoCOld sessions are not blocked by the login enable function. in snipe/snipe-it
- CVE-2022-11561 PoCBooks & Papers <= 0.20210223 - Admin+ Stored Cross-Site Scripting
- CVE-2022-11601 PoCheap buffer overflow in get_one_sourceline in vim/vim
- CVE-2022-11625 PoCsA hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7…
- CVE-2022-11633 PoCsCross-site Scripting (XSS) - Stored in mineweb/minewebcms
- CVE-2022-11641 PoCWyzi < 2.4.3 - Reflected Cross-Site Scripting (XSS)
- CVE-2022-11651 PoCBlackhole for Bad Bots < 3.3.2 - Arbitrary IP Address Blocking via IP Spoofing
- CVE-2022-11661 PoCJobMonster < 4.6.6.1 - Directory Listing in Upload Folder
- CVE-2022-11671 PoCCareerUp < 2.3.1 - Unauthenticated Reflected Cross-Site Scripting
- CVE-2022-11682 PoCsJobSearch < 1.5.1 - Unauthenticated Reflected Cross-Site Scripting (XSS)
- CVE-2022-11691 PoCCareerfy < 3.9.0 - Unauthenticated Reflected Cross-Site Scripting (XSS)
- CVE-2022-11702 PoCsJobMonster < 4.5.2.9 - Unauthenticated Reflected Cross-Site Scripting
- CVE-2022-11711 PoCVertical scroll recent post < 14.0 - Reflected Cross-Site Scripting
- CVE-2022-11721 PoCNull Pointer Dereference Caused Segmentation Fault in gpac/gpac
- CVE-2022-11731 PoCstored xss in getgrav/grav
- CVE-2022-11752 PoCsImproper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all…
- CVE-2022-11761 PoCLoose comparison causes IDOR on multiple endpoints in livehelperchat/livehelperchat
- CVE-2022-11821 PoCVisual Slide Box Builder <= 3.2.9 - Subscriber+ SQLi
- CVE-2022-11911 PoCSSRF on index.php/cobrowse/proxycss/ in livehelperchat/livehelperchat
- CVE-2022-11922 PoCsTurn off all comments <= 1.0 - Reflected Cross-Site Scripting
- CVE-2022-11931 PoCImproper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious…
- CVE-2022-11941 PoCMobile Events Manager < 1.4.8 - Admin+ CSV Injection
- CVE-2022-11961 PoCAfter a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially…
- CVE-2022-12011 PoCNULL Pointer Dereference in mrb_vm_exec with super in mruby/mruby
- CVE-2022-12021 PoCWP-CRM <= 1.2.1 - CSV Injection
- CVE-2022-12032 PoCsContent Mask < 1.8.4.1 - Subscriber+ Arbitrary Options Update
- CVE-2022-12071 PoCOut-of-bounds read in radareorg/radare2
- CVE-2022-12101 PoCLibTIFF tiff2ps resource consumption
- CVE-2022-12111 PoCtildearrow Furnace FUR to VGM Converter stack-based overflow
- CVE-2022-12121 PoCUse-After-Free in str_escape in mruby/mruby in mruby/mruby
- CVE-2022-12131 PoCSSRF filter bypass port 80, 433 in livehelperchat/livehelperchat
- CVE-2022-12161 PoCAdvanced Image Sitemap <= 1.2 - Reflected Cross-Site Scripting
- CVE-2022-12171 PoCCustom TinyMCE Shortcode Button <= 1.1 - Reflected Cross-Site Scripting
- CVE-2022-12181 PoCDomain Replace <= 1.3.8 - Reflected Cross-Site Scripting
- CVE-2022-12191 PoCSQL injection in RecyclebinController.php in pimcore/pimcore
- CVE-2022-12201 PoCFoxyShop < 4.8.2 - Reflected Cross-Site Scripting
- CVE-2022-12212 PoCsGwyn's Imagemap Selector <= 0.3.3 - Reflected Cross-Site Scripting
- CVE-2022-12221 PoCInf loop in gpac/gpac
- CVE-2022-12231 PoCIncorrect Authorization in phpipam/phpipam
- CVE-2022-12241 PoCImproper Authorization in phpipam/phpipam
- CVE-2022-12251 PoCIncorrect Privilege Assignment in phpipam/phpipam
- CVE-2022-12272 PoCsA privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this…
- CVE-2022-12311 PoCXSS via Embedded SVG in SVG Diagram Format in plantuml/plantuml
- CVE-2022-12331 PoCURL Confusion When Scheme Not Supplied in medialize/uri.js
- CVE-2022-12342 PoCsXSS in livehelperchat in livehelperchat/livehelperchat
- CVE-2022-12351 PoCWeak secrethash can be brute-forced in livehelperchat/livehelperchat
- CVE-2022-12371 PoCImproper Validation of Array Index in radareorg/radare2
- CVE-2022-12381 PoCOut-of-bounds Write in libr/bin/format/ne/ne.c in radareorg/radare2
- CVE-2022-12391 PoCHubSpot < 8.8.15 - Contributor+ Blind SSRF
- CVE-2022-12401 PoCHeap buffer overflow in libr/bin/format/mach0/mach0.c in radareorg/radare2
- CVE-2022-12411 PoCAsk Me < 6.8.2 - Reflected Cross-Site Scripting
- CVE-2022-12431 PoCCRHTLF can lead to invalid protocol extraction potentially leading to XSS in medialize/uri.js
- CVE-2022-12441 PoCheap-buffer-overflow in radareorg/radare2
- CVE-2022-12471 PoCAn issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to represent how…
- CVE-2022-12482 PoCsSAP Information System POST Request add_admin.php improper authentication
- CVE-2022-12501 PoCLifterLMS PayPal < 1.4.0 - Reflected Cross-Site Scripting
- CVE-2022-12511 PoCAsk Me < 6.8.4 - CSRF in Edit Profile
- CVE-2022-12522 PoCsUse of a Broken or Risky Cryptographic Algorithm in gnuboard/gnuboard5
- CVE-2022-12551 PoCImport and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-12572 PoCsImproper Verification of Cryptographic Signature by McAfee Agent
- CVE-2022-12631 PoCA NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged…
- CVE-2022-12651 PoCBulletProof Security < 6.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-12661 PoCPost Grid, Slider & Carousel Ultimate < 1.5.0 - Admin+ Stored XSS
- CVE-2022-12671 PoCBMI BMR Calculator <= 1.3 - Reflected Cross-Site Scripting
- CVE-2022-12681 PoCDonate Extra <= 2.02 - Reflected Cross-Site Scripting
- CVE-2022-12691 PoCFast Flow < 1.2.12 - Reflected Cross-Site Scripting
- CVE-2022-12731 PoCImport WP < 2.4.6 - Admin+ Arbitrary File Upload to RCE
- CVE-2022-12741 PoCA flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to…
- CVE-2022-12751 PoCBannerMan <= 0.2.4 - Multiple Admin+ Stored Cross-Site Scripting
- CVE-2022-12761 PoCOut-of-bounds Read in mrb_get_args in mruby/mruby
- CVE-2022-12812 PoCsPhoto Gallery < 1.6.3 - Unauthenticated SQL Injection
- CVE-2022-12821 PoCPhoto Gallery < 1.6.3 - Reflected Cross-Site Scripting
- CVE-2022-12831 PoCNULL Pointer Dereference in r_bin_ne_get_entrypoints function in radareorg/radare2
- CVE-2022-12841 PoCheap-use-after-free in radareorg/radare2
- CVE-2022-12851 PoCServer-Side Request Forgery (SSRF) in gogs/gogs
- CVE-2022-12861 PoCheap-buffer-overflow in mrb_vm_exec in mruby/mruby in mruby/mruby
- CVE-2022-12891 PoCtildearrow Furnace Incomplete Fix CVE-2022-1211 denial of service
- CVE-2022-12901 PoCStored XSS in "Name", "Group Name" & "Title" in polonel/trudesk
- CVE-2022-12911 PoCXSS vulnerability with default `onCellHtmlData` function in hhurz/tableexport.jquery.plugin
- CVE-2022-12925 PoCsThe c_rehash script allows command injection
- CVE-2022-12941 PoCIMDB info box <= 2.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-12951 PoCPrototype Pollution in alvarotrigo/fullpage.js
- CVE-2022-12961 PoCOut-of-bounds read in `r_bin_ne_get_relocs` function in radareorg/radare2
- CVE-2022-12971 PoCOut-of-bounds Read in r_bin_ne_get_entrypoints function in radareorg/radare2
- CVE-2022-12981 PoCTabs Responsive < 2.2.8 - Editor+ Stored Cross-Site Scripting
- CVE-2022-12991 PoCSlideshow <= 2.3.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13011 PoCWP Contact Slider < 2.4.7 - Editor+ Stored Cross-Site Scripting
- CVE-2022-13031 PoCSlide Anything < 2.3.44 - Editor+ Stored Cross-Site Scripting
- CVE-2022-13101 PoCUse after free in regular expressions in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap…
- CVE-2022-13161 PoCIncorrect Permission Assignment for Critical Resource in zerotier/zerotierone
- CVE-2022-13201 PoCSliderby10Web < 1.2.52 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13211 PoCminiOrange's Google Authenticator < 5.5.6 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13221 PoCComing Soon - Under Construction <= 1.1.9 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13231 PoCDiscy < 5.0 - Subscriber+ Broken Access Control to change settings
- CVE-2022-13241 PoCEvent Timeline <= 1.1.5 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13253 PoCsA flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it…
- CVE-2022-13261 PoCForm - Contact Form <= 1.2.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13271 PoCImage Gallery - Grid Gallery < 1.1.6 - Admin+ Stored Cross-Site Scripting
- CVE-2022-132910 PoCsElementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code Execution
- CVE-2022-13341 PoCWP YouTube Live < 1.8.3 - Admin+ Stored Cross Site Scripting
- CVE-2022-13351 PoCSlideshow CK < 1.4.10 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13361 PoCCarousel CK <= 1.1.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13381 PoCEasily Generate Rest API Url <= 1.0.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13391 PoCSQL injection in ElementController.php in pimcore/pimcore
- CVE-2022-13401 PoCCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm
- CVE-2022-13441 PoCStored XSS due to no sanitization in the filename in causefx/organizr
- CVE-2022-13451 PoCStored XSS viva .svg file upload in causefx/organizr
- CVE-2022-13461 PoCMultiple Stored XSS in causefx/organizr
- CVE-2022-13471 PoCStored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in causefx/organizr
- CVE-2022-13491 PoCWPQA < 5.2 - Subscriber+ Arbitrary Profile Picture Deletion via IDOR
- CVE-2022-13511 PoCStored XSS in Tooltip in pimcore/pimcore
- CVE-2022-13541 PoCA heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a…
- CVE-2022-13551 PoCA stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file…
- CVE-2022-13643 PoCsKEVType confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption…
- CVE-2022-13731 PoCSofting Secure Integration Server Relative Path Traversal
- CVE-2022-13791 PoCURL Restriction Bypass in plantuml/plantuml
- CVE-2022-13801 PoCStored Cross Site Scripting vulnerability in Item name parameter in snipe/snipe-it
- CVE-2022-13811 PoCglobal heap buffer overflow in skip_range in vim/vim
- CVE-2022-13821 PoCNULL Pointer Dereference in radareorg/radare2
- CVE-2022-13831 PoCHeap-based Buffer Overflow in radareorg/radare2
- CVE-2022-13869 PoCsFusion Builder < 3.6.2 - Unauthenticated SSRF
- CVE-2022-13871 PoCNo Future Posts <= 1.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-138885 PoCsKEVOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions…
- CVE-2022-13904 PoCsAdmin Word Count Column <= 2.2 - Unauthenticated Arbitrary File Read
- CVE-2022-13913 PoCsCab fare calculator < 1.0.4 - Unauthenticated LFI
- CVE-2022-13923 PoCsVideos sync PDF <= 1.7.4 - Unauthenticated LFI
- CVE-2022-13931 PoCWP Subtitle < 3.4.1 - Contributor+ Stored Cross-Site Scripting
- CVE-2022-13941 PoCPhoto Gallery < 1.6.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13951 PoCEasy FAQ with Expanding Text <= 3.2.8.3.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13962 PoCsDonorbox < 7.1.7 - Admin+ Stored Cross-Site Scripting
- CVE-2022-13971 PoCAPI Privilege Escalation in alextselegidis/easyappointments
- CVE-2022-13982 PoCsExternal Media without Import <= 1.1.2 - Subscriber+ Blind SSRF
- CVE-2022-14071 PoCVikBooking Hotel Booking Engine & PMS < 1.5.7 - Stored Cross-Site Scripting via CSRF
- CVE-2022-14081 PoCVikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ Stored Cross-Site Scripting
- CVE-2022-14091 PoCVikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ PHP File Upload
- CVE-2022-14111 PoCUnrestructed file upload in yetiforcecompany/yetiforcecrm
- CVE-2022-14121 PoCLog WP_Mail <= 0.1 - Email Logs Publicly Accessible
- CVE-2022-14161 PoCMissing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all…
- CVE-2022-14181 PoCSocial Stickers <= 2.2.9 - Stored Cross-Site Scripting via CSRF
- CVE-2022-14201 PoCUse of Out-of-range Pointer Offset in vim/vim
- CVE-2022-14212 PoCsDiscy < 5.2 - Settings Update via CSRF
- CVE-2022-14221 PoCDiscy < 5.2 - Restore Default Settings via CSRF
- CVE-2022-14241 PoCAsk Me < 6.8.2 - Multiple CSRF in AJAX Actions
- CVE-2022-14251 PoCWPQA < 5.2 - Subscriber+ Private Message Disclosure via IDOR
- CVE-2022-14271 PoCOut-of-bounds Read in mrb_obj_is_kind_of in in mruby/mruby
- CVE-2022-14291 PoCSQL injection in GridHelperService.php in pimcore/pimcore
- CVE-2022-14301 PoCCross-site Scripting (XSS) - DOM in octoprint/octoprint
- CVE-2022-14321 PoCCross-site Scripting (XSS) - Generic in octoprint/octoprint
- CVE-2022-14351 PoCWPCargo Track & Trace < 6.9.5 - Admin+ Stored Cross Site Scripting
- CVE-2022-14361 PoCWPCargo Track & Trace < 6.9.5 - Reflected Cross Site Scripting
- CVE-2022-14371 PoCHeap-based Buffer Overflow in radareorg/radare2
- CVE-2022-14381 PoCKeycloak: xss on impersonation under specific circumstances
- CVE-2022-14392 PoCsReflected XSS on demo.microweber.org/demo/module/ in microweber/microweber
- CVE-2022-14401 PoCCommand Injection vulnerability in git-interface@2.1.1 in yarkeev/git-interface
- CVE-2022-14411 PoCMP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it…
- CVE-2022-14423 PoCsMetform Elementor Contact Form Builder <= 2.1.3 - Sensitive Information Disclosure
- CVE-2022-14441 PoCheap-use-after-free in radareorg/radare2
- CVE-2022-14451 PoCStored Cross Site Scripting vulnerability in the checked_out_to parameter in snipe/snipe-it
- CVE-2022-14511 PoCOut-of-bounds Read in r_bin_java_constant_value_attr_new function in radareorg/radare2
- CVE-2022-14521 PoCOut-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in radareorg/radare2
- CVE-2022-14531 PoCRSVPMaker <= 9.2.5 - Unauthenticated SQL Injection
- CVE-2022-14551 PoCCall Now Button < 1.1.2 - Reflected Cross-Site Scripting
- CVE-2022-14561 PoCPoll Maker < 4.0.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-14571 PoCStore XSS in title parameter executing at EditUser Page & EditProducto page in neorazorx/facturascripts
- CVE-2022-14581 PoCStored XSS Leads To Session Hijacking in openemr/openemr
- CVE-2022-14621 PoCAn out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a race condition…
- CVE-2022-14641 PoCStored xss bug in gogs/gogs
- CVE-2022-14651 PoCWPC Smart Wishlist for WooCommerce < 2.9.9 - Reflected Cross-Site Scripting
- CVE-2022-14662 PoCsDue to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to…
- CVE-2022-14691 PoCFiboSearch < 1.18.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-14701 PoCUltimate WooCommerce CSV Importer <= 2.0 - Reflected Cross-Site Scripting
- CVE-2022-147113 PoCsRemote Code execution in SnakeYAML
- CVE-2022-14721 PoCBetter Find and Replace < 1.3.6 - Admin+ SQLi
- CVE-2022-14741 PoCWP Event Manager < 3.1.28 - Reflected Cross-Site Scripting
- CVE-2022-15031 PoCGetSimple CMS Content Module edit.php cross site scripting
- CVE-2022-15041 PoCXSS in /demo/module/?module=HERE in microweber/microweber
- CVE-2022-15061 PoCWP Born Babies <= 1.0 - Contributor+ Stored Cross-Site Scripting
- CVE-2022-15071 PoCchafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service…
- CVE-2022-15091 PoCCommand Injection Vulnerability in hestiacp/hestiacp
- CVE-2022-15111 PoCMissing Authorization in snipe/snipe-it
- CVE-2022-15122 PoCsScrollReveal.js Effects <= 1.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-15141 PoCStored XSS via upload plugin functionality in zip format in neorazorx/facturascripts
- CVE-2022-15271 PoCWP 2FA < 2.2.1 - Reflected Cross-Site Scripting
- CVE-2022-15281 PoCVikBooking < 1.5.9 - Reflected Cross-Site Scripting
- CVE-2022-15301 PoCCross-site Scripting (XSS) in livehelperchat/livehelperchat
- CVE-2022-15311 PoCSQL injection vulnerability in ARAX-UI Synonym Lookup functionality in rtxteam/rtx
- CVE-2022-15321 PoCThemify - WooCommerce Product Filter < 1.3.8 - Reflected Cross-Site Scripting
- CVE-2022-15331 PoCBuffer Over-read in bfabiszewski/libmobi
- CVE-2022-15341 PoCBuffer Over-read at parse_rawml.c:1416 in bfabiszewski/libmobi
- CVE-2022-15371 PoCfile.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in gruntjs/grunt
- CVE-2022-15381 PoCTheme-Demo-Importer < 1.1.1 - Admin+ Arbitrary File Upload
- CVE-2022-15391 PoCExports and Reports < 0.9.2 - Contributor+ CSV Injection
- CVE-2022-15401 PoCPostmagThemes Demo <= 1.0.7 - Admin+ Arbitrary File Upload
- CVE-2022-15411 PoCVideo Slider - Slider Carousel < 1.4.8 - Admin+ Stored Cross-Site Scripting
- CVE-2022-15421 PoCHPB Dashboard <= 1.3.1 - Admin+ Stored Cross Site Scripting
- CVE-2022-15431 PoCImproper handling of Length parameter in erudika/scoold
- CVE-2022-15441 PoCFormula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in luyadev/yii-helpers
- CVE-2022-15461 PoCWooCommerce - Product Importer <= 1.5.2 - Reflected Cross-Site Scripting
- CVE-2022-15471 PoCCheck & Log email < 1.0.6 - Reflected Cross-Site Scripting
- CVE-2022-15491 PoCWP Athletics <= 1.1.7 - Subscriber+ Stored Cross-Site Scripting
- CVE-2022-15511 PoCSP Project & Document Manager < 4.58 - Sensitive File Disclosure
- CVE-2022-15521 PoCA flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another…
- CVE-2022-15531 PoCLeaking password protected articles content due to improper access control in publify/publify
- CVE-2022-15541 PoCPath Traversal due to `send_file` call in clinical-genomics/scout
- CVE-2022-15551 PoCDOM XSS in microweber ver 1.2.15 in microweber/microweber
- CVE-2022-15562 PoCsStaffList < 3.1.5 - Admin+ SQLi
- CVE-2022-15572 PoCsULeak Security & Monitoring <= 1.2.3 - Subscriber+ Stored Cross-Site Scripting
- CVE-2022-15582 PoCsCurtain <= 1.0.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-15592 PoCsClipr <= 1.2.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-15601 PoCAmministrazione Aperta < 3.8 - Admin+ LFI
- CVE-2022-15621 PoCEnable SVG < 1.4.0 - Author+ Stored Cross Site Scripting via SVG
- CVE-2022-15631 PoCWPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure
- CVE-2022-15641 PoCForm Maker By 10Web < 1.14.12 - Admin+ Stored Cross-Site Scripting
- CVE-2022-15653 PoCsImport any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
- CVE-2022-15661 PoCQuotes llama < 1.0.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-15681 PoCTeam Members < 5.1.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-15691 PoCWordPress Forms by Pie Forms < 1.4.9.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-15701 PoCFiles Download Delay < 1.0.7 - Subscriber+ Settings Reset
- CVE-2022-15711 PoCCross-site scripting - Reflected in Create Subaccount in neorazorx/facturascripts
- CVE-2022-15721 PoCHTML2WP <= 1.0.0 - Subscriber+ Arbitrary File Deletion
- CVE-2022-15731 PoCHTML2WP <= 1.0.0 - Arbitrary Settings Update via CSRF
- CVE-2022-15742 PoCsHTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload
- CVE-2022-15751 PoCArbitrary Code Execution through Sanitizer Bypass in jgraph/drawio
- CVE-2022-15761 PoCWP Maintenance Mode & Coming Soon < 2.4.5 - Subscribed Users Deletion via CSRF
- CVE-2022-15771 PoCDatabase Backup for WordPress < 2.5.2 - Arbitrary Schedule Settings Update via CSRF
- CVE-2022-15781 PoCMy wpdb < 2.5 - Arbitrary SQL Query via CSRF
- CVE-2022-15791 PoCLogin Block IPs <= 1.0.0 - IP Spoofing Bypass
- CVE-2022-15802 PoCsSite Offline < 1.5.3 - Access Bypass
- CVE-2022-15811 PoCWP-Polls < 2.76.0 - IP Validation Bypass
- CVE-2022-15821 PoCExternal Links in New Window / New Tab < 1.43 - Unauthenticated Stored Cross-Site Scripting
- CVE-2022-15831 PoCExternal Links in New Window / New Tab < 1.43 - Tabnabbing
- CVE-2022-15841 PoCReflected XSS in microweber/microweber
- CVE-2022-15851 PoCProject Source Code Download <= 1.0.0 - Unauthenticated Backup Download
- CVE-2022-15891 PoCChange wp-admin Login < 1.1.0 - Unauthenticated Arbitrary Settings Update
- CVE-2022-15901 PoCBludit New Content Module new-content cross site scripting
- CVE-2022-15911 PoCWordPress Ping Optimizer < 2.35.1.3.0 - Arbitrary Settings Update via CSRF
- CVE-2022-15923 PoCsServer-Side Request Forgery in scout in clinical-genomics/scout
- CVE-2022-15931 PoCSite Offline or Coming Soon <= 1.6.6 - Stored Cross-Site Scripting via CSRF
- CVE-2022-15941 PoCHC Custom WP-Admin URL <= 1.4 - Arbitrary Settings Update via CSRF
- CVE-2022-15952 PoCsHC Custom WP-Admin URL <= 1.4 - Unauthenticated Secret URL Disclosure
- CVE-2022-15973 PoCsWPQA < 5.4 - Reflected Cross-Site Scripting
- CVE-2022-15983 PoCsWPQA < 5.5 - Unauthenticated Private Message Disclosure
- CVE-2022-15991 PoCAdmin Management Xtended < 2.4.5 - Post Visibility/Date/Comment Status Update via CSRF
- CVE-2022-16001 PoCYOP Poll < 6.4.3 - IP Spoofing
- CVE-2022-16011 PoCUser Access Manager < 2.2.18 - IP Spoofing
- CVE-2022-16031 PoCMail Subscribe List < 2.1.4 - Arbitrary Subscribed User Deletion via CSRF
- CVE-2022-16041 PoCMailerLite < 1.5.4 - Reflected Cross-Site Scripting
- CVE-2022-16051 PoCEmail Users <= 4.8.8 - Arbitrary Settings Update via CSRF
- CVE-2022-16081 PoCOnePress Social Locker <= 5.6.2 - Arbitrary Settings Update via CSRF
- CVE-2022-160912 PoCsThe School Management < 9.9.7 - Unauthenticated RCE via REST api
- CVE-2022-16101 PoCSeamless Donations < 5.1.9 - Arbitrary Settings Update via CSRF
- CVE-2022-16111 PoCBulk Page Creator < 1.1.4 - Arbitrary Page Creation via CSRF
- CVE-2022-16121 PoCWebriti SMTP Mail <= 1.0 - Arbitrary Settings Update via CSRF
- CVE-2022-16131 PoCRestricted Site Access < 7.3.2 - Access Bypass via IP Spoofing
- CVE-2022-16141 PoCWP-Email < 2.69.0 - Anti-Spam Protection Bypass via IP Spoofing
- CVE-2022-16161 PoCUse after free in append_command in vim/vim
- CVE-2022-16171 PoCWP-Invoice <= 4.3.1 - Stored Cross-Site Scripting via CSRF
- CVE-2022-16181 PoCCoru LFMember <= 1.0.2 - Stored Cross-Site Scripting via CSRF
- CVE-2022-16191 PoCHeap-based Buffer Overflow in function cmdline_erase_chars in vim/vim
- CVE-2022-16201 PoCNULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in vim/vim
- CVE-2022-16211 PoCHeap buffer overflow in vim_strncpy find_word in vim/vim
- CVE-2022-16241 PoCLatest Tweets Widget <= 1.1.4 - Arbitrary Settings Update via CSRF
- CVE-2022-16251 PoCNew User Approve < 2.4 - Arbitrary Settings Update & Invitation Code Creation via CSRF
- CVE-2022-16261 PoCSharebar <= 1.4.1 - Arbitrary Settings Update to Stored XSS via CSRF
- CVE-2022-16271 PoCMy Private Site < 3.0.8 - Arbitrary Settings Update via CSRF
- CVE-2022-16291 PoCBuffer Over-read in function find_next_quote in vim/vim
- CVE-2022-16301 PoCWP-Email < 2.69.0 - Log Deletion via CSRF
- CVE-2022-16313 PoCsUsers Account Pre-Takeover or Users Account Takeover. in microweber/microweber
- CVE-2022-16431 PoCBirthdays Widget <= 1.7.18 - Admin+ Stored Cross Site Scripting
- CVE-2022-16441 PoCCall&Book Mobile Bar <= 1.2.2 - Admin+ Stored Cross Site Scripting
- CVE-2022-16451 PoCAmazon Link <= 3.2.10 - Admin+ Stored Cross-Site Scripting
- CVE-2022-16461 PoCSimple Real Estate Pack <= 1.4.8 - Admin+ Stored Cross Site Scripting
- CVE-2022-16471 PoCFormCraft Basic < 1.2.6 - Admin+ Stored Cross Site Scripting
- CVE-2022-16491 PoCNull pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in radareorg/radare2
- CVE-2022-16501 PoCImproper Removal of Sensitive Information Before Storage or Transfer in eventsource/eventsource
- CVE-2022-16531 PoCSocial Share Buttons by Supsystic < 2.2.4 - Multiple CSRF
- CVE-2022-16631 PoCStop Spam Comments <= 0.2.1.2 - Access Token Bypass
- CVE-2022-16721 PoCInsights from Google PageSpeed < 4.0.7 - Multiple CSRF
- CVE-2022-16731 PoCWooCommerce Green Wallet Gateway < 1.0.2 - Reflected Cross Site Scripting in checkout page
- CVE-2022-16741 PoCNULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in vim/vim
- CVE-2022-16811 PoCAuthentication Bypass Using an Alternate Path or Channel in requarks/wiki
- CVE-2022-16821 PoCReflected Xss using url based payload in neorazorx/facturascripts
- CVE-2022-16831 PoCamtyThumb <= 4.2.0 - Subscriber+ SQLi
- CVE-2022-16842 PoCsCube Slider <= 1.2 - Admin+ SQLi
- CVE-2022-16852 PoCsFive Minute Webshop <= 1.3.2 - Admin+ SQLi via orderby
- CVE-2022-16861 PoCFive Minute Webshop <= 1.3.2 - Admin+ SQLi via id
- CVE-2022-16872 PoCsLogo Slider <= 1.4.8 - Admin+ SQLi
- CVE-2022-16882 PoCsNote Press <= 0.1.10 - Admin+ SQLi via id
- CVE-2022-16892 PoCsNote Press <= 0.1.10 - Admin+ SQLi via Update
- CVE-2022-16902 PoCsNote Press <= 0.1.10 - Admin+ SQLi via Bulk Actions
- CVE-2022-16912 PoCsRealty Workstation < 1.0.15 - Agent SQLi
- CVE-2022-16923 PoCsCP Image Store with Slideshow < 1.0.68 - Unauthenticated SQLi
- CVE-2022-16941 PoCUseful Banner Manager <= 1.6.1 - Modify banners via CSRF
- CVE-2022-16951 PoCWP Simple Adsense Insertion < 2.1 - Inject ads and javascript via CSRF
- CVE-2022-16981 PoCAllowing long password leads to denial of service in causefx/organizr
- CVE-2022-16991 PoCUncontrolled Resource Consumption in causefx/organizr
- CVE-2022-17091 PoCThrows SPAM Away < 3.3.1 - Comment Deletion via CSRF
- CVE-2022-17101 PoCAppointment Hour Booking < 1.3.56 - Admin+ Stored Cross-Site Scripting
- CVE-2022-17112 PoCsServer-Side Request Forgery (SSRF) in jgraph/drawio
- CVE-2022-17121 PoCLiveSync for WordPress <= 1.0 - Arbitrary Settings Update via CSRF
- CVE-2022-17132 PoCsSSRF on /proxy in jgraph/drawio
- CVE-2022-17141 PoCOut-of-bounds Read in radareorg/radare2
- CVE-2022-17151 PoCAccount Takeover in neorazorx/facturascripts
- CVE-2022-17161 PoCKeep My Notes v1.80.147 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to…
- CVE-2022-17171 PoCCustom Share Buttons with Floating Sidebar < 4.2 - Admin+ Stored XSS
- CVE-2022-17181 PoCThe trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can allow attackers to…
- CVE-2022-17191 PoCReflected XSS on ticket filter function in polonel/trudesk
- CVE-2022-17201 PoCBuffer Over-read in function grab_file_name in vim/vim
- CVE-2022-17211 PoCPath Traversal in WellKnownServlet in jgraph/drawio
- CVE-2022-17221 PoCSSRF in editor's proxy via IPv6 link-local address in jgraph/drawio
- CVE-2022-17231 PoCServer-Side Request Forgery (SSRF) in jgraph/drawio
- CVE-2022-17242 PoCsSimple Membership < 4.1.1 - Reflected Cross-Site Scripting
- CVE-2022-17251 PoCNULL Pointer Dereference in vim/vim
- CVE-2022-17261 PoCBootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in wenzhixin/bootstrap-table
- CVE-2022-17271 PoCImproper Input Validation in jgraph/drawio
- CVE-2022-17281 PoCAllowing long password leads to denial of service in polonel/trudesk in polonel/trudesk
- CVE-2022-17301 PoCCross-site Scripting (XSS) - Stored in jgraph/drawio
- CVE-2022-17311 PoCMetasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System…
- CVE-2022-17321 PoCRename wp-login.php <= 2.6.0 - Secret URL Update via CSRF
- CVE-2022-17331 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-17351 PoCClassic Buffer Overflow in vim/vim
- CVE-2022-17521 PoCUnrestricted Upload of File with Dangerous Type in polonel/trudesk
- CVE-2022-17532 PoCsWoWonder Group requests.php access control
- CVE-2022-17541 PoCInteger Overflow or Wraparound in polonel/trudesk
- CVE-2022-17551 PoCSVG Support < 2.5 - Author+ Stored Cross-Site Scripting
- CVE-2022-17562 PoCsNewsletter < 7.4.5 - Reflected Cross-Site Scripting
- CVE-2022-17571 PoCPagebar < 2.70 - Arbitrary Settings Update via CSRF to Stored XSS
- CVE-2022-17581 PoCGenki Pre-Publish Reminder <= 1.4.1 - Stored XSS & RCE via CSRF
- CVE-2022-17591 PoCRB Internal Links <= 2.0.16 - Stored Cross-Site Scripting via CSRF
- CVE-2022-17601 PoCCore Control <= 1.2.1 - Arbitrary Settings Update via CSRF
- CVE-2022-17611 PoCPeter’s Collaboration E-mails <= 2.2.0 - Arbitrary Settings Update via CSRF
- CVE-2022-17621 PoCiQ Block Country < 1.2.20 - Protection Bypass due to IP Spoofing
- CVE-2022-17631 PoCStatic Page eXtended <= 2.1 - Arbitrary Settings Update via CSRF to Stored XSS
- CVE-2022-17641 PoCWP-chgFontSize <= 1.8 - Arbitrary Settings Update via CSRF to Stored XSS
- CVE-2022-17651 PoCHot Linked Image Cacher <= 1.16 - Image upload/cache abuse via CSRF
- CVE-2022-17671 PoCServer-Side Request Forgery (SSRF) in jgraph/drawio
- CVE-2022-17682 PoCsRSVPMaker <= 9.3.2 - Unauthenticated SQL Injection
- CVE-2022-17701 PoCImproper Privilege Management in polonel/trudesk
- CVE-2022-17711 PoCUncontrolled Recursion in vim/vim
- CVE-2022-17721 PoCGoogle Places Review < 2.0.0 - Admin+ Stored Cross Site Scripting
- CVE-2022-17731 PoCWP Athletics <= 1.1.7 - Reflected Cross-Site Scripting
- CVE-2022-17741 PoCExposure of Sensitive Information to an Unauthorized Actor in jgraph/drawio
- CVE-2022-17751 PoCWeak Password Requirements in polonel/trudesk
- CVE-2022-17761 PoCIcegram < 2.1.8 - Contributor+ Stored Cross-Site Scripting
- CVE-2022-17771 PoCFilr - Secure Document Library < 1.2.2.1 - Subscriber+ AJAX Calls
- CVE-2022-17791 PoCAuto Delete Posts <= 1.3.0 - Arbitrary Settings Update via CSRF
- CVE-2022-17801 PoCLaTeX for WordPress <= 3.4.10 - Arbitrary Settings Update via CSRF to Stored XSS
- CVE-2022-17811 PoCpostTabs <= 2.10.6 - Arbitrary Settings Update via CSRF to Stored XSS
- CVE-2022-17821 PoCCross-site Scripting (XSS) - Generic in erudika/para
- CVE-2022-17841 PoCServer-Side Request Forgery (SSRF) in jgraph/drawio
- CVE-2022-17851 PoCOut-of-bounds Write in vim/vim
- CVE-2022-17862 PoCsA use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with…
- CVE-2022-17871 PoCSideblog <= 6.0 - Arbitrary Settings Update via CSRF to Stored XSS
- CVE-2022-17881 PoCChange Uploaded File Permissions <= 4.0.0 - File Permission Update via CSRF
- CVE-2022-17901 PoCNew User Email Set Up <= 0.5.2 - Arbitrary Settings Update via CSRF
- CVE-2022-17911 PoCOne Click Plugin Updater <= 2.4.14 - Arbitrary Settings Update via CSRF
- CVE-2022-17921 PoCQuick Subscribe <= 1.7.1 - Arbitrary Settings Update via CSRF to Stored XSS
- CVE-2022-17931 PoCPrivate Files <= 0.40 - Protection Disabling via CSRF
- CVE-2022-17951 PoCUse After Free in gpac/gpac
- CVE-2022-17961 PoCUse After Free in vim/vim
- CVE-2022-18001 PoCExport any WordPress data to XML/CSV < 1.3.5 - Admin+ SQL Injection
- CVE-2022-18011 PoCVery Simple Contact Form < 11.6 - Captcha bypass
- CVE-2022-18021 PoCIf an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved…
- CVE-2022-18031 PoCImproper Restriction of Rendered UI Layers or Frames in polonel/trudesk
- CVE-2022-18061 PoCCross-site Scripting (XSS) - Reflected in rtxteam/rtx
- CVE-2022-18091 PoCAccess of Uninitialized Pointer in radareorg/radare2
- CVE-2022-18101 PoCAuthorization Bypass Through User-Controlled Key in publify/publify
- CVE-2022-18111 PoCUnrestricted Upload of File with Dangerous Type in publify/publify
- CVE-2022-18121 PoCInteger Overflow or Wraparound in publify/publify
- CVE-2022-18131 PoCOS Command Injection in yogeshojha/rengine
- CVE-2022-18141 PoCWP Admin Style <= 0.1.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-18152 PoCsExposure of Sensitive Information to an Unauthorized Actor in jgraph/drawio
- CVE-2022-18181 PoCMulti-page Toolkit <= 2.6 - Arbitrary Settings Update to Stored XSS via CSRF
- CVE-2022-18251 PoCCross-site Scripting (XSS) - Reflected in collectiveaccess/providence
- CVE-2022-18261 PoCCross-Linker <= 3.0.1.9 - Arbitrary Cross-Link Creation via CSRF
- CVE-2022-18271 PoCPDF24 Article To PDF <= 4.2.2 - Arbitrary Settings Update via CSRF
- CVE-2022-18281 PoCPDF24 Articles To PDF <= 4.2.2 - Arbitrary Settings Update via CSRF
- CVE-2022-18291 PoCInline Google Maps <= 5.11 - Arbitrary Settings Update to Stored XSS via CSRF
- CVE-2022-18301 PoCAmazon Einzeltitellinks <= 1.3.3 - Arbitrary Settings Update to Stored XSS via CSRF
- CVE-2022-18311 PoCWPlite <= 1.3.1 - Arbitrary Settings Update via CSRF
- CVE-2022-18321 PoCCaPa Protect <= 0.5.8.2 - Arbitrary Settings Update via CSRF
- CVE-2022-18371 PoCHome Clean Services Management System unrestricted upload
- CVE-2022-18381 PoCHome Clean Services Management System login.php sql injection
- CVE-2022-18391 PoCHome Clean Services Management System login.php sql injection
- CVE-2022-18421 PoCOpenBook Book Data <= 3.5.2 - Arbitrary Settings Update to Stored XSS via CSRF
- CVE-2022-18431 PoCMailPress <= 7.2.1 - Arbitrary Settings Update & Log Files Purge via CSRF
- CVE-2022-18441 PoCWP Sentry <= 1.0 - Arbitrary Settings Update to Stored XSS via CSRF
- CVE-2022-18451 PoCWP Post Styling < 1.3.1 - Multiple CSRF
- CVE-2022-18461 PoCTiny Contact Form <= 0.7 - Arbitrary Settings Update via CSRF
- CVE-2022-18471 PoCRotating Posts <= 1.11 - Arbitrary Settings Update to Stored XSS via CSRF
- CVE-2022-18481 PoCBusiness Logic Errors in erudika/para
- CVE-2022-18491 PoCSession Fixation in filegator/filegator
- CVE-2022-18501 PoCPath Traversal in filegator/filegator
- CVE-2022-18511 PoCOut-of-bounds Read in vim/vim
- CVE-2022-18832 PoCsSQL Injection in camptocamp/terraboard
- CVE-2022-18851 PoCCimy Header Image Rotator <= 6.1.1 - Arbitrary Settings Update via CSRF
- CVE-2022-18861 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-18891 PoCNewsletter < 7.4.6 - Admin+ Stored Cross-Site Scripting
- CVE-2022-18931 PoCImproper Removal of Sensitive Information Before Storage or Transfer in polonel/trudesk
- CVE-2022-18941 PoCPopup Builder < 4.1.11 - Admin+ Stored Cross-Site Scripting
- CVE-2022-18951 PoCunderConstruction < 1.20 - Construction Mode Deactivation via CSRF
- CVE-2022-18961 PoCunderConstruction < 1.21 - Admin+ Stored Cross-Site Scripting
- CVE-2022-18971 PoCOut-of-bounds Write in vim/vim
- CVE-2022-18981 PoCUse After Free in vim/vim
- CVE-2022-18991 PoCOut-of-bounds Read in radareorg/radare2
- CVE-2022-19033 PoCsARMember < 3.4.8 - Unauthenticated Admin Account Takeover
- CVE-2022-19042 PoCsEasy Pricing Tables < 3.2.1 - Reflected Cross-Site-Scripting
- CVE-2022-19051 PoCEvents Made Easy < 2.2.81 - Unauthenticated SQLi
- CVE-2022-19062 PoCsCopyright Proof <= 4.16 - Reflected Cross-Site-Scripting
- CVE-2022-19071 PoCBuffer Over-read in bfabiszewski/libmobi
- CVE-2022-19081 PoCBuffer Over-read in bfabiszewski/libmobi
- CVE-2022-19091 PoCCross-site Scripting (XSS) - Stored in causefx/organizr
- CVE-2022-19102 PoCsShortcodes and extra features for Phlox theme < 2.9.8 - Reflected Cross-Site-Scripting
- CVE-2022-19131 PoCAdd Post URL <= 2.1.0 - Arbitrary Settings Update to Stored XSS via CSRF
- CVE-2022-19141 PoCClean-Contact <= 1.6 - Arbitrary Settings Update to Stored XSS via CSRF
- CVE-2022-19151 PoCWP Zillow Review Slider < 2.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-19162 PoCsActive Products Tables for WooCommerce < 1.0.5 - Reflected Cross-Site-Scripting
- CVE-2022-19211 PoCInteger overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for…
- CVE-2022-19221 PoCDOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in…
- CVE-2022-19231 PoCDOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matroskademux element in bzip decompression…
- CVE-2022-19241 PoCDOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression…
- CVE-2022-19251 PoCDOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in…
- CVE-2022-19261 PoCInteger Overflow or Wraparound in polonel/trudesk
- CVE-2022-19271 PoCBuffer Over-read in vim/vim
- CVE-2022-19281 PoCCross-site Scripting (XSS) - Stored in go-gitea/gitea
- CVE-2022-19291 PoCExponential ReDoS in devcert
- CVE-2022-19301 PoCReDoS in eth-account encode_structured_data function
- CVE-2022-19311 PoCIncorrect Synchronization in polonel/trudesk
- CVE-2022-19321 PoCRezgo Online Booking < 4.1.8 - Reflected Cross-Site-Scripting
- CVE-2022-19332 PoCsCDI < 5.1.9 - Reflected Cross-Site-Scripting
- CVE-2022-19341 PoCUse After Free in mruby/mruby
- CVE-2022-19372 PoCsAwin Data Feed < 1.8 - Reflected Cross-Site Scripting
- CVE-2022-19381 PoCAwin Data Feed < 1.8 - Unauthenticated Stored Cross-Site Scripting
- CVE-2022-19391 PoCAllow SVG Files < 1.1 - Admin+ Arbitrary File Upload
- CVE-2022-19421 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-19451 PoCComing Soon and Maintenance by Colorlib < 1.0.99 - Admin+ Stored Cross Site Scripting
- CVE-2022-19462 PoCsGallery < 2.0.0 - Reflected Cross-Site Scripting
- CVE-2022-19471 PoCUse of Incorrect Operator in polonel/trudesk
- CVE-2022-19503 PoCsYouzify < 1.2.0 - Unauthenticated SQLi
- CVE-2022-19511 PoCCore Plugin for Kitestudio Themes < 2.3.1 - Reflected Cross-Site-Scripting
- CVE-2022-19522 PoCseaSYNC < 1.1.16 - Unauthenticated Arbitrary File Upload
- CVE-2022-19531 PoCProduct Configurator for WooCommerce < 1.2.32 - Unauthenticated Arbitrary File Deletion
- CVE-2022-19552 PoCsSession 1.13.0 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user…
- CVE-2022-19561 PoCShortcut Macros <= 1.3 - Subscriber+ Arbitrary Settings Update
- CVE-2022-19571 PoCComment License < 1.4.0 - Arbitrary Settings Update via CSRF
- CVE-2022-19601 PoCMyCSS <= 1.1 - Arbitrary Settings Update via CSRF
- CVE-2022-19611 PoCGoogle Tag Manager for WordPress (GTM4WP) <= 1.15.1 - Stored Cross-Site Scripting via Content Element ID
- CVE-2022-19641 PoCEasy SVG Support < 3.3.0 - Author+ Stored Cross Site Scripting via SVG
- CVE-2022-19671 PoCWP Championship < 9.3 - Multiple CSRF
- CVE-2022-19681 PoCUse After Free in vim/vim
- CVE-2022-19711 PoCNextCellent Gallery <= 1.9.35 - Admin+ Stored XSS
- CVE-2022-19771 PoCWP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRF
- CVE-2022-19861 PoCOS Command Injection in gogs/gogs
- CVE-2022-19871 PoCBuffer Over-read in bfabiszewski/libmobi
- CVE-2022-19881 PoCCross-site Scripting (XSS) - Generic in neorazorx/facturascripts
- CVE-2022-19901 PoCNested Pages < 3.1.21 - Admin+ Stored Cross Site Scripting
- CVE-2022-19911 PoCFast Food Ordering System Master List Master.php cross site scripting
- CVE-2022-19921 PoCPath Traversal in gogs/gogs
- CVE-2022-19931 PoCPath Traversal in gogs/gogs
- CVE-2022-19941 PoCGoogle Authenticator < 1.0.8 - Admin+ Stored Cross-Site Scripting
- CVE-2022-19951 PoCminiOrange's Malware Scanner < 4.5.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-19961 PoCAuthorization Bypass Through User-Controlled Key in emicklei/go-restful
- CVE-2022-19971 PoCCross-site Scripting (XSS) - Stored in francoisjacquet/rosariosis