CVE-2022-29000 to CVE-2022-29999
177 CVEs with public proof-of-concept exploits.
- CVE-2022-290021 PoCA Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component…
- CVE-2022-290042 PoCsDiary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in…
- CVE-2022-290052 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows…
- CVE-2022-290063 PoCsMultiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0…
- CVE-2022-290073 PoCsMultiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System…
- CVE-2022-290082 PoCsAn insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to…
- CVE-2022-290093 PoCsMultiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project…
- CVE-2022-290134 PoCsA command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary…
- CVE-2022-290143 PoCsA local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.
- CVE-2022-290171 PoCBento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64/multiarch/strlen-avx2.S.
- CVE-2022-290211 PoCA buffer overflow vulnerability exists in the razerkbd driver of OpenRazer up to version v3.3.0 allows attackers to cause a Denial of…
- CVE-2022-290221 PoCA buffer overflow vulnerability exists in the razeraccessory driver of OpenRazer up to version v3.3.0 allows attackers to cause a Denial…
- CVE-2022-290231 PoCA buffer overflow vulnerability exists in the razermouse driver of OpenRazer up to version v3.3.0 allows attackers to cause a Denial of…
- CVE-2022-290342 PoCsA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). An error message pop up window in the web…
- CVE-2022-290562 PoCsA improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0…
- CVE-2022-290631 PoCJava Deserialization via RMI Connection from the Solr plugin of Apache OFBiz
- CVE-2022-290725 PoCs7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the…
- CVE-2022-2907831 PoCsThe ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view…
- CVE-2022-290801 PoCThe npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions…
- CVE-2022-290812 PoCsZoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to…
- CVE-2022-291531 PoCHashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent…
- CVE-2022-291541 PoCAn issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of…
- CVE-2022-291701 PoCGrafana Enterprise datasource network restrictions bypass via HTTP redirects
- CVE-2022-291811 PoCImproper Handling of Unexpected Data Type in Nokogiri
- CVE-2022-292131 PoCIncomplete validation in signal ops leads to crashes in TensorFlow
- CVE-2022-292211 PoCPHP Code Injection by malicious block or filename in Smarty
- CVE-2022-292251 PoCZip bomb vulnerability in Envoy
- CVE-2022-292721 PoCIn Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
- CVE-2022-292961 PoCA reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute…
- CVE-2022-292983 PoCsSolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
- CVE-2022-293038 PoCsKEVSolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
- CVE-2022-293041 PoCOnline Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /classes/master.php?f=delete_ Facility.
- CVE-2022-293051 PoCimgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost.
- CVE-2022-293151 PoCInvicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV feature is used.
- CVE-2022-293161 PoCComplete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via…
- CVE-2022-293201 PoCMiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- CVE-2022-293211 PoCD-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.
- CVE-2022-293221 PoCD-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip.
- CVE-2022-293231 PoCD-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.
- CVE-2022-293241 PoCD-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.
- CVE-2022-293251 PoCD-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter parameter in /goform/websURLFilter.
- CVE-2022-293261 PoCD-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter.
- CVE-2022-293271 PoCD-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in /goform/websURLFilterAddDel.
- CVE-2022-293281 PoCD-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade.
- CVE-2022-293291 PoCD-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a heap overflow via the devicename parameter in /goform/setDeviceSettings.
- CVE-2022-293321 PoCD-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder…
- CVE-2022-293332 PoCsA vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.
- CVE-2022-293371 PoCC-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6.…
- CVE-2022-293391 PoCIn GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of…
- CVE-2022-293401 PoCGPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper…
- CVE-2022-293471 PoCAn arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
- CVE-2022-293492 PoCskkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at…
- CVE-2022-293511 PoCAn arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a…
- CVE-2022-293581 PoCepub2txt2 v2.04 was discovered to contain an integer overflow via the function bug in _parse_special_tag at sxmlc.c. This vulnerability…
- CVE-2022-293592 PoCsA stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows…
- CVE-2022-293601 PoCThe Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.
- CVE-2022-293612 PoCsImproper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted…
- CVE-2022-293631 PoCPhpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. This vulnerability…
- CVE-2022-293681 PoCModdable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function…
- CVE-2022-293802 PoCsAcademy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
- CVE-2022-293833 PoCsNETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via…
- CVE-2022-293911 PoCTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004200c8.
- CVE-2022-293921 PoCTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418c24.
- CVE-2022-293931 PoCTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004192cc.
- CVE-2022-293941 PoCTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macAddress parameter in the function FUN_0041b448.
- CVE-2022-293951 PoCTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the apcliKey parameter in the function FUN_0041bac4.
- CVE-2022-293961 PoCTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418f10.
- CVE-2022-293971 PoCTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004196c8.
- CVE-2022-293981 PoCTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the File parameter in the function FUN_0041309c.
- CVE-2022-293991 PoCTOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the url parameter in the function FUN_00415bf0.
- CVE-2022-294558 PoCsWordPress Elementor plugin <= 3.5.5 - Unauthenticated DOM-based Reflected Cross-Site Scripting (XSS) vulnerability
- CVE-2022-294572 PoCsZoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash…
- CVE-2022-294581 PoCncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the…
- CVE-2022-2946448 PoCsKEVCertain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint…
- CVE-2022-294652 PoCsAn out-of-bounds write vulnerability exists in the PSD Header processing memory allocation functionality of Accusoft ImageGear 20.0. A…
- CVE-2022-294681 PoCA cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP…
- CVE-2022-294721 PoCAn OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc. iota All-In-One…
- CVE-2022-294751 PoCAn information disclosure vulnerability exists in the XFINDER functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and…
- CVE-2022-294771 PoCAn authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc. iota All-In-One…
- CVE-2022-294811 PoCA leftover debug code vulnerability exists in the console nvram functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted…
- CVE-2022-294951 PoCWordPress Popup Builder plugin <= 4.1.11 - Cross-Site Request Forgery (CSRF) leading to plugin settings update
- CVE-2022-294961 PoCA stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A…
- CVE-2022-294991 PoCKEVThe Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data…
- CVE-2022-295031 PoCA memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread…
- CVE-2022-295111 PoCA directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweeper lansweeper…
- CVE-2022-295171 PoCA directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A…
- CVE-2022-295201 PoCAn OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc. iota All-In-One Security…
- CVE-2022-295371 PoCgp_rtp_builder_do_hevc in ietf/rtp_pck_mpeg4.c in GPAC 2.0.0 has a heap-based buffer over-read, as demonstrated by MP4Box.
- CVE-2022-295485 PoCsA reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0,…
- CVE-2022-295661 PoCThe Bulletproofs 2017/1066 paper mishandles Fiat-Shamir generation because the hash computation fails to include all of the public values…
- CVE-2022-295771 PoCOWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly…
- CVE-2022-295813 PoCsImproper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root.…
- CVE-2022-295823 PoCsIn the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered…
- CVE-2022-295871 PoCKonica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access…
- CVE-2022-295934 PoCsrelay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the…
- CVE-2022-295961 PoCMicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the…
- CVE-2022-295971 PoCSolutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the…
- CVE-2022-295981 PoCSolutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via…
- CVE-2022-296031 PoCA SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select parameter to multiple API endpoints. A…
- CVE-2022-296142 PoCsSAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL…
- CVE-2022-296202 PoCsFileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does…
- CVE-2022-296222 PoCsAn arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some…
- CVE-2022-296312 PoCsJodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and…
- CVE-2022-296381 PoCTOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the comment parameter…
- CVE-2022-296401 PoCTOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the comment parameter…
- CVE-2022-296411 PoCTOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and…
- CVE-2022-296421 PoCTOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the url parameter in…
- CVE-2022-296431 PoCTOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the macAddress…
- CVE-2022-296461 PoCAn access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allows attackers to obtain sensitive…
- CVE-2022-296522 PoCsOnline Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=save_client.
- CVE-2022-296541 PoCBuffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2.15.05 allows attackers to cause a denial of service via…
- CVE-2022-296591 PoCResponsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.
- CVE-2022-296601 PoCCSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.
- CVE-2022-296611 PoCCSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at…
- CVE-2022-296631 PoCCSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy.
- CVE-2022-296641 PoCCSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2022-296661 PoCCSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2022-296671 PoCCSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability…
- CVE-2022-296691 PoCCSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2022-296701 PoCCSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2022-296761 PoCCSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2022-296801 PoCCSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del.
- CVE-2022-296811 PoCCSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del.
- CVE-2022-296821 PoCCSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at…
- CVE-2022-296831 PoCCSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at…
- CVE-2022-296841 PoCCSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at…
- CVE-2022-296851 PoCCSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at…
- CVE-2022-296861 PoCCSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at…
- CVE-2022-296871 PoCCSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at…
- CVE-2022-296881 PoCCSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at…
- CVE-2022-296891 PoCCSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at…
- CVE-2022-296921 PoCUnicorn Engine v1.0.3 was discovered to contain a use-after-free vulnerability via the hook function.
- CVE-2022-296931 PoCUnicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc.c.
- CVE-2022-296941 PoCUnicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free.
- CVE-2022-296951 PoCUnicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization.
- CVE-2022-297041 PoCBrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.
- CVE-2022-297091 PoCCommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and…
- CVE-2022-297211 PoC74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.
- CVE-2022-297272 PoCsSurvey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.
- CVE-2022-297291 PoCVerizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates…
- CVE-2022-297301 PoCUSR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account.…
- CVE-2022-297321 PoCDelta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vulnerability via…
- CVE-2022-297331 PoCDelta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext.…
- CVE-2022-297351 PoCDelta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request.
- CVE-2022-297701 PoCXXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.
- CVE-2022-297751 PoCiSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
- CVE-2022-297761 PoCOnlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component…
- CVE-2022-297771 PoCOnlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component…
- CVE-2022-297781 PoCD-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor'…
- CVE-2022-297791 PoCNginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.
- CVE-2022-297801 PoCNginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_prototype_sort at src/njs_array.c.
- CVE-2022-297994 PoCsA vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the…
- CVE-2022-298004 PoCsA time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a…
- CVE-2022-298064 PoCsZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary…
- CVE-2022-298071 PoCA SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code…
- CVE-2022-298242 PoCsIn libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows.…
- CVE-2022-298542 PoCsA vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated…
- CVE-2022-298552 PoCsMitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series…
- CVE-2022-298562 PoCsA hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.
- CVE-2022-298581 PoCSilverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by…
- CVE-2022-298853 PoCsEncryptInterceptor does not provide complete protection on insecure networks
- CVE-2022-298861 PoCAn integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a…
- CVE-2022-298881 PoCA leftover debug code vulnerability exists in the httpd port 4444 upload.cgi functionality of InHand Networks InRouter302 V3.5.45. A…
- CVE-2022-298891 PoCA hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a…
- CVE-2022-299121 PoCRequests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird <…
- CVE-2022-299151 PoCThe Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability…
- CVE-2022-299161 PoCFirefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been…
- CVE-2022-299321 PoCThe HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the…
- CVE-2022-299332 PoCsCraft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password…
- CVE-2022-299381 PoCIn LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via…
- CVE-2022-299391 PoCIn LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to…
- CVE-2022-299401 PoCIn LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to…
- CVE-2022-299483 PoCsDue to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an authentication bypass attack that enables…
- CVE-2022-299501 PoCExperian Hunter 1.16 allows remote authenticated users to modify assumed-immutable elements via the (1) rule name parameter to the Rules…
- CVE-2022-299681 PoCAn issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
- CVE-2022-299771 PoCThere is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could…
- CVE-2022-299781 PoCThere is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could…