CVE-2022-25000 to CVE-2022-25999
273 CVEs with public proof-of-concept exploits.
- CVE-2022-250031 PoCHospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in…
- CVE-2022-250041 PoCHospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in…
- CVE-2022-250124 PoCsArgus Surveillance DVR v4.0 employs weak password encryption.
- CVE-2022-250131 PoCIce Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm"…
- CVE-2022-250141 PoCIce Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of…
- CVE-2022-250151 PoCA stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted…
- CVE-2022-250171 PoCHitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.
- CVE-2022-250182 PoCsPluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
- CVE-2022-250202 PoCsA cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2022-250222 PoCsA cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in…
- CVE-2022-250231 PoCAudio File commit 004065d was discovered to contain a heap-buffer overflow in the function fouBytesToInt():AudioFile.h.
- CVE-2022-250261 PoCA Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on…
- CVE-2022-250441 PoCEspruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.
- CVE-2022-250451 PoCHome Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate…
- CVE-2022-250461 PoCA path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
- CVE-2022-250471 PoCThe password reset token in CWP v0.9.8.1126 is generated using known or predictable values.
- CVE-2022-250481 PoCCommand injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
- CVE-2022-250601 PoCTP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
- CVE-2022-250612 PoCsTP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
- CVE-2022-250622 PoCsTP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability…
- CVE-2022-250643 PoCsTP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function…
- CVE-2022-250721 PoCTP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This…
- CVE-2022-250731 PoCTL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability…
- CVE-2022-250741 PoCTP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This…
- CVE-2022-250751 PoCTOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This…
- CVE-2022-250761 PoCTOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This…
- CVE-2022-250771 PoCTOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This…
- CVE-2022-250781 PoCTOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This…
- CVE-2022-250791 PoCTOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" function. This…
- CVE-2022-250801 PoCTOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability…
- CVE-2022-250811 PoCTOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability…
- CVE-2022-250822 PoCsTOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the…
- CVE-2022-250831 PoCTOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This…
- CVE-2022-250843 PoCsTOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability…
- CVE-2022-250892 PoCsPrintix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via…
- CVE-2022-250903 PoCsPrintix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions,…
- CVE-2022-250941 PoCHome Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the parameter…
- CVE-2022-250951 PoCHome Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.
- CVE-2022-250961 PoCHome Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in…
- CVE-2022-251041 PoCHorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/.
- CVE-2022-251061 PoCD-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows…
- CVE-2022-251141 PoCEvent Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name parameter under…
- CVE-2022-251151 PoCA remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection…
- CVE-2022-251252 PoCsMCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
- CVE-2022-251391 PoCnjs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.
- CVE-2022-251484 PoCsWP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_id
- CVE-2022-251492 PoCsWP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via IP
- CVE-2022-251653 PoCsAn issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files.…
- CVE-2022-251663 PoCsAn issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when…
- CVE-2022-251711 PoCCommand Injection
- CVE-2022-251721 PoCAn information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4.…
- CVE-2022-251731 PoCJenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the…
- CVE-2022-251741 PoCJenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for…
- CVE-2022-251751 PoCJenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the…
- CVE-2022-252162 PoCsAn absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user…
- CVE-2022-252202 PoCsPeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descriptions while…
- CVE-2022-252211 PoCMoney Transfer Management System Version 1.0 allows an attacker to inject JavaScript code in the URL and then trick a user into visit the…
- CVE-2022-252221 PoCMoney Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php'…
- CVE-2022-252231 PoCMoney Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in…
- CVE-2022-252241 PoCProton v0.2.0 allows an attacker to create a malicious link inside a markdown file. When the victim clicks the link, the application opens…
- CVE-2022-252251 PoCNetwork Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON…
- CVE-2022-252263 PoCsThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by…
- CVE-2022-252271 PoCThinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if…
- CVE-2022-252281 PoCCandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'userID'…
- CVE-2022-252292 PoCsPopcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is…
- CVE-2022-252351 PoCxmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is…
- CVE-2022-252361 PoCxmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
- CVE-2022-252374 PoCsBonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the…
- CVE-2022-252412 PoCsIn FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
- CVE-2022-252561 PoCSAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and…
- CVE-2022-252581 PoCAn issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain…
- CVE-2022-252601 PoCJetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
- CVE-2022-252621 PoCIn JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
- CVE-2022-252951 PoCOpen Redirect
- CVE-2022-252961 PoCPrototype Pollution
- CVE-2022-252973 PoCsArbitrary File Write
- CVE-2022-252981 PoCPath Traversal
- CVE-2022-252991 PoCArbitrary File Write
- CVE-2022-253012 PoCsPrototype Pollution
- CVE-2022-253051 PoCWP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via IP
- CVE-2022-253061 PoCWP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via browser
- CVE-2022-253071 PoCWP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via platform
- CVE-2022-253081 PoCA stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the…
- CVE-2022-253091 PoCA heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the…
- CVE-2022-253101 PoCA segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the…
- CVE-2022-253132 PoCsIn Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
- CVE-2022-253141 PoCIn Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
- CVE-2022-253153 PoCsIn Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
- CVE-2022-253221 PoCZEROF Web Server 2.0 allows /HandleEvent SQL Injection.
- CVE-2022-253231 PoCZEROF Web Server 2.0 allows /admin.back XSS.
- CVE-2022-253241 PoCDenial of Service (DoS)
- CVE-2022-253301 PoCInteger overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the…
- CVE-2022-253311 PoCUncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remote attacker to…
- CVE-2022-253421 PoCAn issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken Access Control. It…
- CVE-2022-253431 PoCAn issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Denial of Service. An…
- CVE-2022-253441 PoCAn XSS issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application doesn't properly check parameters,…
- CVE-2022-253451 PoCDenial of Service (DoS)
- CVE-2022-253492 PoCsCross-site Scripting (XSS)
- CVE-2022-253501 PoCAll versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
- CVE-2022-253521 PoCPrototype Pollution
- CVE-2022-253541 PoCPrototype Pollution
- CVE-2022-253561 PoCAlt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.
- CVE-2022-253592 PoCsOn ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
- CVE-2022-253651 PoCDocker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for…
- CVE-2022-253692 PoCsAn issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists…
- CVE-2022-253722 PoCsPritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in…
- CVE-2022-253731 PoCZoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.
- CVE-2022-253751 PoCAn issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation…
- CVE-2022-253931 PoCSimple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
- CVE-2022-253941 PoCMedical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php.
- CVE-2022-253951 PoCCosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the…
- CVE-2022-253961 PoCCosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
- CVE-2022-253981 PoCAuto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
- CVE-2022-253991 PoCSimple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
- CVE-2022-254021 PoCAn incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
- CVE-2022-254031 PoCHMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.
- CVE-2022-254071 PoCHospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at…
- CVE-2022-254081 PoCHospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at…
- CVE-2022-254091 PoCHospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at…
- CVE-2022-254111 PoCA Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted…
- CVE-2022-254121 PoCMaxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via…
- CVE-2022-254141 PoCTenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.
- CVE-2022-254171 PoCTenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.
- CVE-2022-254181 PoCTenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.
- CVE-2022-254271 PoCTenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.
- CVE-2022-254281 PoCTenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo function.
- CVE-2022-254291 PoCTenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo function.
- CVE-2022-254311 PoCTenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the Formsetqosband…
- CVE-2022-254331 PoCTenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the saveparentcontrolinfo function.
- CVE-2022-254341 PoCTenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg function.
- CVE-2022-254351 PoCTenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg function.
- CVE-2022-254371 PoCTenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.
- CVE-2022-254381 PoCTenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function.
- CVE-2022-254391 PoCTenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.
- CVE-2022-254401 PoCTenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.
- CVE-2022-254411 PoCTenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg…
- CVE-2022-254451 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.
- CVE-2022-254461 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSchedWifi function.
- CVE-2022-254471 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.
- CVE-2022-254481 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the day parameter in the openSchedWifi function.
- CVE-2022-254491 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.
- CVE-2022-254501 PoCTenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.
- CVE-2022-254513 PoCsTenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the setstaticroutecfg function.
- CVE-2022-254521 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the URLs parameter in the saveParentControlInfo function.
- CVE-2022-254531 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function.
- CVE-2022-254541 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function.
- CVE-2022-254551 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.
- CVE-2022-254561 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the security_5g parameter in the WifiBasicSet function.
- CVE-2022-254571 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.
- CVE-2022-254581 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the cmdinput parameter in the exeCommand function.
- CVE-2022-254591 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function.
- CVE-2022-254601 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function.
- CVE-2022-254611 PoCTenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the startip parameter in the SetPptpServerCfg function.
- CVE-2022-254651 PoCEspruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling.
- CVE-2022-254771 PoCVulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card…
- CVE-2022-254781 PoCVulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card…
- CVE-2022-254792 PoCsVulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card…
- CVE-2022-254801 PoCVulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card…
- CVE-2022-254813 PoCsThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system…
- CVE-2022-254841 PoCtcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.
- CVE-2022-254852 PoCsCuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.
- CVE-2022-254863 PoCsCuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.
- CVE-2022-254874 PoCsAtom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.
- CVE-2022-254882 PoCsAtom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.
- CVE-2022-254891 PoCAtom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.
- CVE-2022-254901 PoCHMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
- CVE-2022-254911 PoCHMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.
- CVE-2022-254921 PoCHMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.
- CVE-2022-254931 PoCHMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.
- CVE-2022-254941 PoCOnline Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php.
- CVE-2022-254951 PoCThe component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary…
- CVE-2022-254972 PoCsCuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.
- CVE-2022-254981 PoCCuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in…
- CVE-2022-255061 PoCFreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser.
- CVE-2022-255111 PoCAn issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files…
- CVE-2022-255141 PoCstb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOTE: Third party has…
- CVE-2022-255151 PoCstb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE: Third party has…
- CVE-2022-255161 PoCstb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbtt__find_table at stb_truetype.h. NOTE: Third…
- CVE-2022-255231 PoCTypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
- CVE-2022-255461 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers…
- CVE-2022-255481 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to…
- CVE-2022-255491 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers…
- CVE-2022-255501 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows…
- CVE-2022-255511 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers…
- CVE-2022-255521 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function form_fast_setting_wifi_set. This vulnerability allows…
- CVE-2022-255531 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers…
- CVE-2022-255541 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows…
- CVE-2022-255551 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to…
- CVE-2022-255561 PoCTenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42E328. This vulnerability allows attackers to…
- CVE-2022-255571 PoCTenda AX1806 v1.0.0.1 was discovered to contain a heap overflow in the function saveParentControlInfo. This vulnerability allows attackers…
- CVE-2022-255581 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetProvince. This vulnerability allows attackers to…
- CVE-2022-255601 PoCTenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_4327CC. This vulnerability allows attackers to…
- CVE-2022-255611 PoCTenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42DE00. This vulnerability allows attackers to…
- CVE-2022-255661 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows…
- CVE-2022-255683 PoCsMotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this…
- CVE-2022-255761 PoCAnchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This…
- CVE-2022-255771 PoCALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user's data. Attackers…
- CVE-2022-255811 PoCClasscms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to…
- CVE-2022-256301 PoCAn authenticated user can embed malicious content with XSS into the admin group policy page.
- CVE-2022-256365 PoCsnet/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds…
- CVE-2022-256401 PoCIn wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the…
- CVE-2022-256441 PoCArbitrary Code Execution
- CVE-2022-256452 PoCsPrototype Pollution
- CVE-2022-256463 PoCsCross-site Scripting (XSS)
- CVE-2022-256481 PoCCommand Injection
- CVE-2022-257582 PoCsRegular Expression Denial of Service (ReDoS)
- CVE-2022-257593 PoCsRemote Code Injection
- CVE-2022-257601 PoCArbitrary Code Injection
- CVE-2022-2576513 PoCsCommand Injection
- CVE-2022-257661 PoCRemote Code Execution (RCE)
- CVE-2022-258101 PoCTransposh WordPress Translation <= 1.0.8 - Subscriber+ Unauthorised Calls
- CVE-2022-258111 PoCTransposh WordPress Translation <= 1.0.8 - Admin+ SQL Injection
- CVE-2022-258121 PoCTransposh WordPress Translation < 1.0.8 - Admin+ RCE
- CVE-2022-258131 PoCServer-Side Template Injection affecting the ecommerce plugin of Apache OFBiz
- CVE-2022-258391 PoCImproper Input Validation
- CVE-2022-258421 PoCArbitrary File Write via Archive Extraction (Zip Slip)
- CVE-2022-258444 PoCsRegular Expression Denial of Service (ReDoS)
- CVE-2022-258455 PoCsDeserialization of Untrusted Data
- CVE-2022-258471 PoCAll versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it…
- CVE-2022-258482 PoCsDirectory Traversal
- CVE-2022-258491 PoCCross-site Scripting (XSS)
- CVE-2022-258501 PoCServer-side Request Forgery (SSRF)
- CVE-2022-258522 PoCsDenial of Service (DoS)
- CVE-2022-258531 PoCAll versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input…
- CVE-2022-258541 PoCCross-site Scripting (XSS)
- CVE-2022-258551 PoCAll versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input…
- CVE-2022-258571 PoCDenial of Service (DoS)
- CVE-2022-258582 PoCsRegular Expression Denial of Service (ReDoS)
- CVE-2022-258601 PoCVersions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and…
- CVE-2022-258621 PoCPrototype Pollution
- CVE-2022-258631 PoCDeserialization of Untrusted Data
- CVE-2022-258652 PoCsCommand Injection
- CVE-2022-258661 PoCCommand Injection
- CVE-2022-258671 PoCNULL Pointer Dereference
- CVE-2022-258697 PoCsAll versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to…
- CVE-2022-258711 PoCPrototype Pollution
- CVE-2022-258721 PoCOut-of-bounds Read
- CVE-2022-258751 PoCCross-site Scripting (XSS)
- CVE-2022-258761 PoCServer-side Request Forgery (SSRF)
- CVE-2022-258782 PoCsPrototype Pollution
- CVE-2022-258812 PoCsThis affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values…
- CVE-2022-258823 PoCsVersions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a…
- CVE-2022-258831 PoCVersions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range,…
- CVE-2022-258901 PoCAll versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.
- CVE-2022-258931 PoCArbitrary Code Execution
- CVE-2022-258952 PoCsDirectory Traversal
- CVE-2022-258984 PoCsImproper Verification of Cryptographic Signature
- CVE-2022-259001 PoCCommand Injection
- CVE-2022-259013 PoCsVersions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse…
- CVE-2022-259042 PoCsPrototype Pollution
- CVE-2022-259061 PoCAll versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes…
- CVE-2022-259071 PoCPrototype Pollution
- CVE-2022-259081 PoCAll versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper…
- CVE-2022-259123 PoCsRemote Code Execution (RCE)
- CVE-2022-259181 PoCRegular Expression Denial of Service (ReDoS)
- CVE-2022-259211 PoCArbitrary Code Execution
- CVE-2022-259231 PoCVersions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper…
- CVE-2022-259272 PoCsVersions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression…
- CVE-2022-259292 PoCsCross-site Scripting (XSS)
- CVE-2022-259312 PoCsDirectory Traversal
- CVE-2022-259362 PoCsVersions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the filePath variable.
- CVE-2022-259371 PoCVersions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root…
- CVE-2022-259403 PoCsDenial of Service (DoS)
- CVE-2022-259421 PoCAn out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead…
- CVE-2022-259432 PoCsThe installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the…
- CVE-2022-259491 PoCThe kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle crafted inputs,…
- CVE-2022-259721 PoCAn out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can…
- CVE-2022-259731 PoCArbitrary Command Execution
- CVE-2022-259781 PoCAll versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on…
- CVE-2022-259792 PoCsVersions of the package jsuites before 5.0.1 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization in the…
- CVE-2022-259891 PoCAn authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A…
- CVE-2022-259951 PoCA command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted…
- CVE-2022-259961 PoCA stack-based buffer overflow vulnerability exists in the confsrv addTimeGroup functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A…