CVE-2022-24000 to CVE-2022-24999
168 CVEs with public proof-of-concept exploits.
- CVE-2022-240041 PoCA Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11. This issue allows any…
- CVE-2022-240051 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240061 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240071 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240081 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240091 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240101 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240111 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240121 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240131 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240141 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240151 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240161 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240171 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240181 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240191 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240201 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240211 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240221 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240231 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240241 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240251 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240261 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240271 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240281 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240291 PoCA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted…
- CVE-2022-240651 PoCCommand Injection
- CVE-2022-240822 PoCsIf an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port…
- CVE-2022-2408610 PoCsKEVAdobe Commerce checkout improper input validation leads to remote code execution
- CVE-2022-241081 PoCThe Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via the setting…
- CVE-2022-2411219 PoCsKEVapisix/batch-requests plugin allows overwriting the X-REAL-IP header
- CVE-2022-241151 PoCLocal privilege escalation due to unrestricted loading of unsigned libraries
- CVE-2022-241211 PoCSQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information…
- CVE-2022-241221 PoCkernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and…
- CVE-2022-2412414 PoCsThe query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by…
- CVE-2022-241251 PoCThe matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send arbitrary push…
- CVE-2022-241261 PoCA buffer overflow in the NRSessionSearchResult parser in Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allows remote…
- CVE-2022-241271 PoCA Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue…
- CVE-2022-241292 PoCsThe OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction…
- CVE-2022-241351 PoCQingScan 1.3.0 is affected by Cross Site Scripting (XSS) vulnerability in all search functions.
- CVE-2022-241361 PoCHospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To…
- CVE-2022-241814 PoCsCross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary…
- CVE-2022-241871 PoCThe user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object reference…
- CVE-2022-241881 PoCThe /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the…
- CVE-2022-241891 PoCThe user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. Removing the value…
- CVE-2022-241901 PoCThe /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is…
- CVE-2022-241911 PoCIn HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting…
- CVE-2022-241961 PoCiText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw,…
- CVE-2022-241971 PoCiText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause…
- CVE-2022-242233 PoCsAtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
- CVE-2022-242271 PoCA cross-site scripting (XSS) vulnerability in BoltWire v7.10 and v 8.00 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2022-242311 PoCSimple Student Information System v1.0 was discovered to contain a SQL injection vulnerability via add/Student.
- CVE-2022-242472 PoCsRiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the…
- CVE-2022-242482 PoCsRiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the…
- CVE-2022-242491 PoCA Null Pointer Dereference vulnerability exists in GPAC 1.1.0 via the xtra_box_write function in /box_code_base.c, which causes a Denial…
- CVE-2022-242511 PoCExtensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload…
- CVE-2022-242521 PoCAn unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to…
- CVE-2022-242531 PoCExtensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component…
- CVE-2022-242541 PoCAn unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to…
- CVE-2022-242551 PoCExtensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.
- CVE-2022-242602 PoCsA SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.
- CVE-2022-242634 PoCsHospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via…
- CVE-2022-242642 PoCsCuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word…
- CVE-2022-242652 PoCsCuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the…
- CVE-2022-242661 PoCCuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by…
- CVE-2022-242781 PoCDirectory Traversal
- CVE-2022-242791 PoCPrototype Pollution
- CVE-2022-242881 PoCApache Airflow: RCE in example DAGs
- CVE-2022-243421 PoCIn JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
- CVE-2022-243541 PoCThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 prior to 1.1.4…
- CVE-2022-243551 PoCThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build…
- CVE-2022-243721 PoCLinksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.
- CVE-2022-243732 PoCsRegular Expression Denial of Service (ReDoS)
- CVE-2022-243761 PoCCommand Injection
- CVE-2022-243771 PoCCommand Injection
- CVE-2022-243841 PoCReflective XSS on SmarterTrack v100.0.8019.14010
- CVE-2022-243962 PoCsThe Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be…
- CVE-2022-243992 PoCsThe SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input name of the file…
- CVE-2022-244051 PoCOX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
- CVE-2022-244061 PoCOX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into…
- CVE-2022-244292 PoCsArbitrary Code Injection
- CVE-2022-244311 PoCCommand Injection
- CVE-2022-244343 PoCsDenial of Service (DoS)
- CVE-2022-244372 PoCsCommand Injection
- CVE-2022-244393 PoCsRemote Code Execution (RCE)
- CVE-2022-244421 PoCJetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
- CVE-2022-244813 PoCsWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-244831 PoCWindows Kernel Information Disclosure Vulnerability
- CVE-2022-244911 PoCWindows Network File System Remote Code Execution Vulnerability
- CVE-2022-244971 PoCWindows Network File System Remote Code Execution Vulnerability
- CVE-2022-245003 PoCsWindows SMB Remote Code Execution Vulnerability
- CVE-2022-245213 PoCsKEVWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-245623 PoCsIn IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access…
- CVE-2022-245711 PoCCar Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection…
- CVE-2022-245741 PoCGPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra ().
- CVE-2022-245752 PoCsGPAC 1.0.1 is affected by a stack-based buffer overflow through MP4Box.
- CVE-2022-245762 PoCsGPAC 1.0.1 is affected by Use After Free through MP4Box.
- CVE-2022-245771 PoCGPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen function.)
- CVE-2022-245781 PoCGPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c.
- CVE-2022-245941 PoCIn waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
- CVE-2022-245951 PoCAutomotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected by Incorrect Access Control in…
- CVE-2022-245991 PoCIn autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an…
- CVE-2022-246111 PoCDenial of Service (DoS) in the Z-Wave S0 NonceGet protocol specification in Silicon Labs Z-Wave 500 series allows local attackers to block…
- CVE-2022-246131 PoCmetadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in…
- CVE-2022-246141 PoCWhen reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally…
- CVE-2022-246201 PoCPiwigo version 12.2.0 is vulnerable to stored cross-site scripting (XSS), which can lead to privilege escalation. In this way, admin can…
- CVE-2022-246272 PoCsAn issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p…
- CVE-2022-246291 PoCAn issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory…
- CVE-2022-246301 PoCAn issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with…
- CVE-2022-246321 PoCAn issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via…
- CVE-2022-2463712 PoCsOpen Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to…
- CVE-2022-246431 PoCA stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0.
- CVE-2022-246443 PoCsZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated update. To exploit…
- CVE-2022-246461 PoCHospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php…
- CVE-2022-246471 PoCCuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.
- CVE-2022-246542 PoCsAuthenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21…
- CVE-2022-246561 PoCHexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opened with the app,…
- CVE-2022-246651 PoCRemote Code Execution by by Contributor+ users via WordPress gutenberg block
- CVE-2022-246751 PoCencoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
- CVE-2022-246761 PoCupdate_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.
- CVE-2022-246771 PoCAdmin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.
- CVE-2022-246812 PoCsZoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User…
- CVE-2022-246823 PoCsKEVAn issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the…
- CVE-2022-246931 PoCBaicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can…
- CVE-2022-2470613 PoCsKEVRemote Code Execution Vulnerability in Packaging
- CVE-2022-247074 PoCsSQL injection in anuko timetracker
- CVE-2022-247132 PoCsRegular expression denial of service in Rust's regex crate
- CVE-2022-247154 PoCsArbitrary code execution for authenticated users in Icinga Web 2
- CVE-2022-247169 PoCsPath traversal in Icinga Web 2
- CVE-2022-247231 PoCImproper Input Validation in URI.js
- CVE-2022-247241 PoCInteger overflow in table parsing extension leads to heap memory corruption
- CVE-2022-247346 PoCsRemote code execution in mybb
- CVE-2022-247551 PoCIncorrect Authorization in Bareos Director
- CVE-2022-247561 PoCMissing Release of Memory after Effective Lifetime in Bareos Director
- CVE-2022-247602 PoCsCommand Injection in Parse server
- CVE-2022-247803 PoCsCode Injection in Combodo iTop
- CVE-2022-247852 PoCsPath Traversal in Moment.js
- CVE-2022-248164 PoCsKEVImproper Control of Generation of Code in jai-ext
- CVE-2022-248181 PoCUnchecked JNDI lookups in GeoTools
- CVE-2022-248191 PoCUnauthenticated user can retrieve the list of users through uorgsuggest.vm
- CVE-2022-248301 PoCPath Traversal in OpenClinica
- CVE-2022-248332 PoCsPersistent Cross-site Scripting (XSS) vulnerability in PrivateBin
- CVE-2022-248344 PoCsHeap overflow issue with the Lua cjson library used by Redis
- CVE-2022-248441 PoCSQL Injection in github.com/flipped-aurora/gin-vue-admin
- CVE-2022-248511 PoCStored XSS and path traversal in LDAPAccountManager/lam
- CVE-2022-248531 PoCFile system exposure in Metabase
- CVE-2022-248561 PoCServer-Side Request Forgery in FlyteConsole
- CVE-2022-248651 PoCImproper access control in humhub
- CVE-2022-248911 PoCCross-site Scripting in org.owasp.esapi:esapi -- antisamy-esapi.xml configuration file
- CVE-2022-248971 PoCArbitrary filesystem write access from Velocity
- CVE-2022-248991 PoCCross site scripting via canonical tag
- CVE-2022-249002 PoCsAbsolute Path Traversal due to incorrect use of `send_file` call in Piano LED Visualizer
- CVE-2022-249101 PoCA buffer overflow vulnerability exists in the httpd parse_ping_result API functionality of InHand Networks InRouter302 V3.5.4. A…
- CVE-2022-249241 PoCAn improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a…
- CVE-2022-249344 PoCswpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry.
- CVE-2022-249491 PoCA privilege escalation to root exists in Eternal Terminal prior to version 6.2.0. This is due to the combination of a race condition,…
- CVE-2022-249501 PoCA race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH…
- CVE-2022-249511 PoCA race condition exists in Eternal Terminal prior to version 6.2.0 which allows a local attacker to hijack Eternal Terminal's IPC socket,…
- CVE-2022-249521 PoCSeveral denial of service vulnerabilities exist in Eternal Terminal prior to version 6.2.0, including a DoS triggered remotely by an…
- CVE-2022-249561 PoCAn issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and…
- CVE-2022-249571 PoCDHC Vision eQMS through 5.4.8.322 has Persistent XSS due to insufficient encoding of untrusted input/output. To exploit the vulnerability,…
- CVE-2022-249761 PoCAtheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a…
- CVE-2022-249771 PoCImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to…
- CVE-2022-249892 PoCsTerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters…
- CVE-2022-2499011 PoCsKEVTerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to…
- CVE-2022-249923 PoCsA vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.
- CVE-2022-249951 PoCTenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers…
- CVE-2022-249991 PoCqs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express…