CVE-2022-26000 to CVE-2022-26999
142 CVEs with public proof-of-concept exploits.
- CVE-2022-260021 PoCA stack-based buffer overflow vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A…
- CVE-2022-260071 PoCAn OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A…
- CVE-2022-260091 PoCA stack-based buffer overflow vulnerability exists in the confsrv ucloud_set_node_location functionality of TCL LinkHub Mesh Wi-Fi…
- CVE-2022-260201 PoCAn information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRouter302 V3.5.4. A…
- CVE-2022-260231 PoCA leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted…
- CVE-2022-260261 PoCA denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform…
- CVE-2022-260421 PoCAn OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4. A…
- CVE-2022-260431 PoCAn external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform…
- CVE-2022-260491 PoCArbitrary File Write via Archive Extraction (Zip Slip)
- CVE-2022-260611 PoCA heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file…
- CVE-2022-260671 PoCAn information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS…
- CVE-2022-260681 PoCPath Traversal
- CVE-2022-260731 PoCA denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h. A…
- CVE-2022-260751 PoCAn OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 V3.5.37. A…
- CVE-2022-260771 PoCA cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications functionality of…
- CVE-2022-260821 PoCA file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform…
- CVE-2022-260851 PoCAn OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A…
- CVE-2022-260883 PoCsAn issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such…
- CVE-2022-261012 PoCsFiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)…
- CVE-2022-261335 PoCsSharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to…
- CVE-2022-2613497 PoCsKEVIn affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated…
- CVE-2022-261353 PoCsA vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the…
- CVE-2022-261386 PoCsKEVThe Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users…
- CVE-2022-261431 PoCKEVThe TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers…
- CVE-2022-261471 PoCThe Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.
- CVE-2022-261482 PoCsAn issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php…
- CVE-2022-261492 PoCsMODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file,…
- CVE-2022-261551 PoCAn issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. XSS can occur via a payload in the…
- CVE-2022-261561 PoCAn issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the…
- CVE-2022-261571 PoCAn issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie is not protected…
- CVE-2022-261581 PoCAn issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains…
- CVE-2022-261593 PoCsThe auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as…
- CVE-2022-261691 PoCAir Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter.
- CVE-2022-261701 PoCSimple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
- CVE-2022-261711 PoCBank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter.
- CVE-2022-261731 PoCJForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which…
- CVE-2022-261802 PoCsqdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
- CVE-2022-261831 PoCPNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when…
- CVE-2022-261971 PoCJoget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.
- CVE-2022-262111 PoCTotolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730,…
- CVE-2022-262333 PoCsBarco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to…
- CVE-2022-262431 PoCTenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow in the setSmartPowerManagement function.
- CVE-2022-262441 PoCA stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary…
- CVE-2022-262491 PoCSurvey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access…
- CVE-2022-262501 PoCSynaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges.
- CVE-2022-262511 PoCThe HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate…
- CVE-2022-262521 PoCaaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain the root user…
- CVE-2022-262541 PoCWoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated…
- CVE-2022-262551 PoCClash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column.
- CVE-2022-262581 PoCKEVD-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
- CVE-2022-262601 PoCSimple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse().
- CVE-2022-262631 PoCYonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.
- CVE-2022-262652 PoCsContao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.
- CVE-2022-262691 PoCSuzuki Connect v1.0.15 allows attackers to tamper with displayed messages via spoofed CAN messages.
- CVE-2022-262711 PoC74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
- CVE-2022-262781 PoCTenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.
- CVE-2022-262791 PoCEyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
- CVE-2022-262811 PoCBigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
- CVE-2022-262841 PoCSimple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client…
- CVE-2022-262911 PoClrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and…
- CVE-2022-262931 PoCOnline Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function…
- CVE-2022-262951 PoCA stored cross-site scripting (XSS) vulnerability in /ptms/?page=user of Online Project Time Management System v1.0 allows attackers to…
- CVE-2022-262961 PoCBOOM: The Berkeley Out-of-Order RISC-V Processor commit d77c2c3 was discovered to allow unauthorized disclosure of information to an…
- CVE-2022-263011 PoCTuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php.
- CVE-2022-263031 PoCAn external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform…
- CVE-2022-263151 PoCqrcp through 0.8.4, in receive mode, allows ../ Directory Traversal via the file name specified by the uploader.
- CVE-2022-263185 PoCsKEVOn WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts…
- CVE-2022-263321 PoCCipi 3.1.15 allows Add Server stored XSS via the /api/servers name field.
- CVE-2022-263421 PoCA buffer overflow vulnerability exists in the confsrv ucloud_set_node_location functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A…
- CVE-2022-263461 PoCA denial of service vulnerability exists in the ucloud_del_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A…
- CVE-2022-263525 PoCsKEVAn issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a…
- CVE-2022-263641 PoCx86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which…
- CVE-2022-263761 PoCA memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New…
- CVE-2022-263771 PoCmod_proxy_ajp: Possible request smuggling
- CVE-2022-263821 PoCWhile the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel…
- CVE-2022-263851 PoCIn unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free…
- CVE-2022-263871 PoCWhen installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the…
- CVE-2022-264201 PoCAn OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 V3.5.37. A…
- CVE-2022-264791 PoCAn issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync…
- CVE-2022-264811 PoCAn issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request…
- CVE-2022-264821 PoCAn issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.
- CVE-2022-264851 PoCKEVRemoving an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild…
- CVE-2022-264881 PoCIn Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may…
- CVE-2022-264951 PoCIn nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the…
- CVE-2022-264961 PoCIn nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the…
- CVE-2022-265031 PoCDeserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code…
- CVE-2022-265101 PoCA firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A…
- CVE-2022-265181 PoCAn OS command injection vulnerability exists in the console infactory_net functionality of InHand Networks InRouter302 V3.5.37. A…
- CVE-2022-265212 PoCsAbantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the…
- CVE-2022-265311 PoCMultiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through…
- CVE-2022-265461 PoCHospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and…
- CVE-2022-265641 PoCHotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in…
- CVE-2022-265652 PoCsA cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web…
- CVE-2022-265852 PoCsMingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
- CVE-2022-265881 PoCA Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the…
- CVE-2022-265921 PoCStack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function.
- CVE-2022-266071 PoCA remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via…
- CVE-2022-266131 PoCPHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.
- CVE-2022-266241 PoCBootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in…
- CVE-2022-266281 PoCMatrimony v1.0 was discovered to contain a SQL injection vulnerability via the Password parameter.
- CVE-2022-266292 PoCsAn Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient…
- CVE-2022-266321 PoCMulti-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in…
- CVE-2022-266331 PoCSimple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php.
- CVE-2022-266341 PoCHMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2022-266351 PoCPHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties…
- CVE-2022-266391 PoCTP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.
- CVE-2022-266401 PoCTP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.
- CVE-2022-266411 PoCTP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.
- CVE-2022-266421 PoCTP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.
- CVE-2022-266531 PoCZoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an…
- CVE-2022-266711 PoCTAIWAN SECOM CO., LTD., a xDoor Access Control and Personnel Attendance Management system - Hard-coded Credentials
- CVE-2022-267171 PoCA use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS…
- CVE-2022-267262 PoCsThis issue was addressed with improved checks. This issue is fixed in Security Update 2022-004 Catalina, watchOS 8.6, macOS Monterey 12.4,…
- CVE-2022-267631 PoCAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5,…
- CVE-2022-267662 PoCsA certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security…
- CVE-2022-267771 PoCZoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.
- CVE-2022-267791 PoCApache Cloudstack insecure random number generation affects project email invitation
- CVE-2022-267801 PoCMultiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302…
- CVE-2022-267811 PoCMultiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302…
- CVE-2022-267821 PoCMultiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302…
- CVE-2022-2680918 PoCsRemote Procedure Call Runtime Remote Code Execution Vulnerability
- CVE-2022-268332 PoCsAn improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A…
- CVE-2022-268421 PoCA reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master…
- CVE-2022-268731 PoCThe stack buffer overflow vulnerability in PlatformInitAdvancedPreMem leads to arbitrary code execution during PEI phase.
- CVE-2022-268841 PoCApache DolphinScheduler exposes files without authentication
- CVE-2022-269041 PoCKEVWindows User Profile Service Elevation of Privilege Vulnerability
- CVE-2022-269239 PoCsKEVActive Directory Domain Services Elevation of Privilege Vulnerability
- CVE-2022-269271 PoCWindows Graphics Component Remote Code Execution Vulnerability
- CVE-2022-269373 PoCsWindows Network File System Remote Code Execution Vulnerability
- CVE-2022-269521 PoCDigi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header string when an…
- CVE-2022-269531 PoCDigi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in the page parameter for…
- CVE-2022-269591 PoCThere are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application.…
- CVE-2022-269601 PoCconnector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to…
- CVE-2022-269655 PoCsIn Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
- CVE-2022-269671 PoCGPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be triggered via MP4Box.
- CVE-2022-269801 PoCTeampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.
- CVE-2022-269811 PoCLiblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by…
- CVE-2022-269822 PoCsSimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php…
- CVE-2022-269862 PoCsSQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker…
- CVE-2022-269871 PoCTP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in…
- CVE-2022-269881 PoCTP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte`…
- CVE-2022-269901 PoCArris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection…