CVE-2022-23000 to CVE-2022-23999
136 CVEs with public proof-of-concept exploits.
- CVE-2022-230051 PoCHost Boot ROM Code Vulnerability in Systems Implementing UFS Boot Feature
- CVE-2022-230431 PoCZenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the…
- CVE-2022-230451 PoCPhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating…
- CVE-2022-230466 PoCsPhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via…
- CVE-2022-230472 PoCsExponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site…
- CVE-2022-230482 PoCsExponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file…
- CVE-2022-230492 PoCsExponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in.…
- CVE-2022-230501 PoCManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside…
- CVE-2022-230511 PoCPeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying…
- CVE-2022-230521 PoCPeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users,…
- CVE-2022-230551 PoCERPNext - Improper user access conrol
- CVE-2022-230561 PoCERPNext - Stored XSS leads to account takover
- CVE-2022-230571 PoCERPNext - Stored XSS in My Profile
- CVE-2022-230581 PoCERPNext - Stored XSS in My Settings
- CVE-2022-230591 PoCShopizer - Stored XSS in Manage Images
- CVE-2022-230601 PoCShopizer - Stored XSS in Manage Files
- CVE-2022-230611 PoCShopizer - IDOR delete superadmin
- CVE-2022-230641 PoCSnipe-IT - Host Header Injection
- CVE-2022-230651 PoCVendure - XSS via SVG File Upload
- CVE-2022-230662 PoCsSolana rBPF - Incorrect Calculation in sdiv instruction
- CVE-2022-230671 PoCToolJet - Token Leakage via Referer Header
- CVE-2022-230681 PoCToolJet - HTML Injection in Invite New User
- CVE-2022-230711 PoCRecipes - SSRF on Import
- CVE-2022-230721 PoCRecipes - Stored XSS in Add to Cart
- CVE-2022-230731 PoCRecipes - Stored XSS in Clipboard
- CVE-2022-230741 PoCRecipes - Stored XSS in Name Parameter
- CVE-2022-230771 PoCHabitica - DOM XSS in login page
- CVE-2022-230781 PoCHabitica - Open redirect in login page
- CVE-2022-230791 PoCmotoradmin - host header Injection in the reset password functionality
- CVE-2022-230801 PoCdirectus - SSRF which leads to internal port scan
- CVE-2022-230811 PoCOpenlibrary - Reflected XSS
- CVE-2022-230821 PoCCureKit - Path Traversal in isFileOutsideDir
- CVE-2022-230872 PoCsBhyve e82545 device emulation out-of-bounds write
- CVE-2022-230932 PoCsStack overflow in ping(8)
- CVE-2022-230991 PoCOX App Suite through 7.10.6 allows XSS by forcing block-wise read.
- CVE-2022-231001 PoCOX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
- CVE-2022-231011 PoCOX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
- CVE-2022-231023 PoCsA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect…
- CVE-2022-231031 PoCA stack-based buffer overflow vulnerability exists in the confsrv confctl_set_app_language functionality of TCL LinkHub Mesh Wi-Fi…
- CVE-2022-231192 PoCsA directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below…
- CVE-2022-231202 PoCsA code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could…
- CVE-2022-2313126 PoCsKEVUnsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
- CVE-2022-231343 PoCsKEVPossible view of the setup pages by unauthenticated users if config file already exists
- CVE-2022-231784 PoCsAn issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is…
- CVE-2022-231791 PoCContact Form & Lead Form Elementor Builder < 1.7.0 - Multiple Admin+ Stored Cross-Site Scripting
- CVE-2022-231801 PoCContact Form & Lead Form Elementor Builder Plugin < 1.7.4 - Multiple Subscriber+ Settings Update
- CVE-2022-232201 PoCUSBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit…
- CVE-2022-232216 PoCsH2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the…
- CVE-2022-232227 PoCskernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer…
- CVE-2022-232272 PoCsKEVNUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary…
- CVE-2022-232531 PoCWindows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
- CVE-2022-232701 PoCWindows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-232772 PoCsMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2022-233052 PoCsSQL injection in JDBC Appender in Apache Log4j V1
- CVE-2022-233161 PoCAn issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via…
- CVE-2022-233201 PoCXMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default…
- CVE-2022-233211 PoCA persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when editing users in the…
- CVE-2022-233321 PoCCommand injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532…
- CVE-2022-233421 PoCThe Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to…
- CVE-2022-233451 PoCBigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
- CVE-2022-233461 PoCBigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.
- CVE-2022-233472 PoCsBigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
- CVE-2022-233482 PoCsBigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
- CVE-2022-233491 PoCBigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).
- CVE-2022-233501 PoCBigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.
- CVE-2022-233521 PoCAn issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
- CVE-2022-233641 PoCHMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php.
- CVE-2022-233651 PoCHMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php.
- CVE-2022-233663 PoCsHMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.
- CVE-2022-233671 PoCFulusso v1.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in /BindAccount/SuccessTips.js. This…
- CVE-2022-233771 PoCArcheevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files.
- CVE-2022-233781 PoCA Cross-Site Scripting (XSS) vulnerability exists within the 3.2.2 version of TastyIgniter. The "items%5B0%5D%5Bpath%5D" parameter of a…
- CVE-2022-233841 PoCYzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add
- CVE-2022-233901 PoCAn issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.
- CVE-2022-233971 PoCThe Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly sanitize data…
- CVE-2022-233991 PoCA stack-based buffer overflow vulnerability exists in the confsrv set_port_fwd_rule functionality of TCL LinkHub Mesh Wifi…
- CVE-2022-234001 PoCA stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft ImageGear 19.10. A…
- CVE-2022-234093 PoCsThe Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
- CVE-2022-234571 PoCPath Traversal in ESAPI
- CVE-2022-234581 PoCToast UI Grid vulnerable to Cross-site scripting
- CVE-2022-234611 PoCCross-Site Scripting (XSS) in Jodit Editor
- CVE-2022-234631 PoCSpEL Injection in Nepxion Discovery
- CVE-2022-234641 PoCPotential Server Side Request Forgery (SSRF) in Nepxion Discovery
- CVE-2022-234741 PoCeditor.js contains Code Injection
- CVE-2022-235121 PoCMetersphere is vulnerable to Path Injection.
- CVE-2022-235132 PoCsPi-Hole/AdminLTE vulnerable due to improper access control in queryads endpoint
- CVE-2022-235201 PoCrails-html-sanitizer contains an incomplete fix for an XSS vulnerability
- CVE-2022-235222 PoCsArbitrary File Write when Extracting Tarballs retrieved from a remote location using in mindsdb
- CVE-2022-235302 PoCsGuardDog vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI package
- CVE-2022-235442 PoCsServer-Side Request Forgery in Metersphere leads to Cross-Site Scripting
- CVE-2022-235551 PoCauthentik vulnerable to Improper Authentication via invitation URL token reuse
- CVE-2022-235961 PoCInfinite loop in junrar
- CVE-2022-236144 PoCsCode injection in Twig
- CVE-2022-236262 PoCsInsufficient file checks in m1k1o/blog
- CVE-2022-236362 PoCsInvalid drop of partially-initialized instances in wasmtime
- CVE-2022-236426 PoCsCode Injection in Sourcegraph
- CVE-2022-236484 PoCsInsecure handling of image volumes in containerd CRI plugin
- CVE-2022-237311 PoCV8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.
- CVE-2022-237733 PoCscmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead…
- CVE-2022-237794 PoCsZoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered…
- CVE-2022-237931 PoC[20220301] - Core - Zip Slip within the Tar extractor
- CVE-2022-238031 PoCA stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality…
- CVE-2022-238041 PoCA stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality…
- CVE-2022-238084 PoCsAn issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can…
- CVE-2022-238122 PoCsMalicious Package
- CVE-2022-238503 PoCsxhtml_translate_entity in xhtml.c in epub2txt (aka epub2txt2) through 2.02 allows a stack-based buffer overflow via a crafted EPUB document.
- CVE-2022-238521 PoCExpat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
- CVE-2022-238543 PoCsAVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated…
- CVE-2022-238611 PoCMultiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web…
- CVE-2022-238621 PoCA Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to…
- CVE-2022-238651 PoCNyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vulnerability, an…
- CVE-2022-238781 PoCseacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
- CVE-2022-238812 PoCsZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
- CVE-2022-238821 PoCTuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.
- CVE-2022-238841 PoCMojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by…
- CVE-2022-238871 PoCYzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via…
- CVE-2022-238881 PoCYzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.
- CVE-2022-238961 PoCAdmidio 4.1.2 version is affected by stored cross-site scripting (XSS).
- CVE-2022-238982 PoCsMCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
- CVE-2022-238991 PoCMCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
- CVE-2022-239001 PoCA command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve…
- CVE-2022-239071 PoCCMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.
- CVE-2022-239093 PoCsThere is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local…
- CVE-2022-239111 PoCAP Custom Testimonial < 1.4.8 - Admin+ SQL Injection
- CVE-2022-239121 PoCAP Custom Testimonial < 1.4.8 - Reflected Cross-Site Scripting
- CVE-2022-239181 PoCA stack-based buffer overflow vulnerability exists in the confsrv set_mf_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A…
- CVE-2022-239191 PoCA stack-based buffer overflow vulnerability exists in the confsrv set_mf_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A…
- CVE-2022-239232 PoCsSandbox Bypass
- CVE-2022-239355 PoCslib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.
- CVE-2022-239403 PoCsSuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports…
- CVE-2022-239442 PoCsApache ShenYu 2.4.1 Improper access control
- CVE-2022-239461 PoCA stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA…
- CVE-2022-239681 PoCXerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF…
- CVE-2022-239871 PoCWS Form < 1.8.176 - Admin+ Stored Cross-Site Scripting
- CVE-2022-239881 PoCWS Form < 1.8.176 - Unauthenticated Stored Cross-Site Scripting
- CVE-2022-239902 PoCsExpat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.