CVE-2022-2000 to CVE-2022-2999
414 CVEs with public proof-of-concept exploits.
- CVE-2022-20001 PoCOut-of-bounds Write in vim/vim
- CVE-2022-20141 PoCCode Injection in jgraph/drawio
- CVE-2022-20151 PoCCross-site Scripting (XSS) - Stored in jgraph/drawio
- CVE-2022-20161 PoCCross-site Scripting (XSS) - Reflected in neorazorx/facturascripts
- CVE-2022-20191 PoCSourceCodester Prison Management System New User Creation improper authorization
- CVE-2022-20221 PoCCross-site Scripting (XSS) - Stored in nocodb/nocodb
- CVE-2022-20231 PoCIncorrect Use of Privileged APIs in polonel/trudesk
- CVE-2022-20241 PoCOS Command Injection in gogs/gogs
- CVE-2022-20251 PoCGrandstream GSD3710 Stack-based Buffer Overflow
- CVE-2022-20261 PoCCross-site Scripting (XSS) - Stored in kromitgmbh/titra
- CVE-2022-20271 PoCImproper Neutralization of Formula Elements in a CSV File in kromitgmbh/titra
- CVE-2022-20281 PoCCross-site Scripting (XSS) - Generic in kromitgmbh/titra
- CVE-2022-20291 PoCCross-site Scripting (XSS) - DOM in kromitgmbh/titra
- CVE-2022-20342 PoCsSensei LMS < 4.5.0 - Unauthenticated Private Messages Disclosure via Rest API
- CVE-2022-20351 PoCA reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/modern.html file for…
- CVE-2022-20361 PoCCross-site Scripting (XSS) - Stored in francoisjacquet/rosariosis
- CVE-2022-20371 PoCExcessive Attack Surface in tooljet/tooljet
- CVE-2022-20401 PoCBrizy Page Builder < 2.4.2 - Contributor+ Stored Cross-Site Scripting via Element URL
- CVE-2022-20411 PoCBrizy Page Builder < 2.4.2 - Contributor+ Stored Cross-Site Scripting via Element Content
- CVE-2022-20421 PoCUse After Free in vim/vim
- CVE-2022-20461 PoCDirectorist - Business Directory Plugin < 7.2.3 - Admin+ Arbitrary File Upload
- CVE-2022-20501 PoCWP Paginate < 2.1.9 - Admin+ Stored Cross-Site Scripting
- CVE-2022-20541 PoCCode Injection in nuitka/nuitka
- CVE-2022-20561 PoCDivide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that…
- CVE-2022-20571 PoCDivide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that…
- CVE-2022-20581 PoCDivide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that…
- CVE-2022-20601 PoCCross-site Scripting (XSS) - Stored in dolibarr/dolibarr
- CVE-2022-20611 PoCHeap-based Buffer Overflow in hpjansson/chafa
- CVE-2022-20621 PoCGeneration of Error Message Containing Sensitive Information in nocodb/nocodb
- CVE-2022-20631 PoCImproper Privilege Management in nocodb/nocodb
- CVE-2022-20641 PoCInsufficient Session Expiration in nocodb/nocodb
- CVE-2022-20661 PoCCross-site Scripting (XSS) - Reflected in neorazorx/facturascripts
- CVE-2022-20671 PoCSQL Injection in francoisjacquet/rosariosis
- CVE-2022-20681 PoCThe c_rehash script allows command injection
- CVE-2022-20701 PoCGrandstream GSD3710 Stack-based Buffer Overflow
- CVE-2022-20711 PoCName Directory < 1.25.4 - Stored Cross-Site Scripting via CSRF
- CVE-2022-20721 PoCName Directory < 1.25.3 - Reflected Cross-Site Scripting
- CVE-2022-20732 PoCsCode Injection in getgrav/grav
- CVE-2022-20781 PoCA vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer…
- CVE-2022-20791 PoCCross-site Scripting (XSS) - Stored in nocodb/nocodb
- CVE-2022-20831 PoCSimple Single Sign On <= 4.1.0 - Authentication Bypass
- CVE-2022-20851 PoCA NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory.…
- CVE-2022-20861 PoCSourceCodester Bank Management System login.php sql injection
- CVE-2022-20871 PoCSourceCodester Bank Management System cross site scripting
- CVE-2022-20891 PoCBold Page Builder < 4.3.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-20901 PoCWoo Discount Rules < 2.4.2 - Reflected Cross-Site Scripting
- CVE-2022-20911 PoCCache Images < 3.2.1 - Image Upload / Import via CSRF
- CVE-2022-20921 PoCWooCommerce PDF Invoices & Packing Slips < 2.16.0 - Reflected Cross-Site Scripting
- CVE-2022-20931 PoCWP Duplicate Page < 1.3 - Admin+ Stored Cross Site Scripting
- CVE-2022-20941 PoCYellow Yard Searchbar < 2.8.2 - Reflected Cross-Site Scripting
- CVE-2022-20981 PoCWeak Password Requirements in kromitgmbh/titra
- CVE-2022-20991 PoCWooCommerce < 6.6.0 - Admin+ Stored HTML Injection
- CVE-2022-21001 PoCPage Generator Plugin < 1.6.5 - Admin+ Stored Cross-Site Scripting
- CVE-2022-21012 PoCsDownload Manager <= 3.2.46 - Contributor+ Cross-Site Scripting
- CVE-2022-21111 PoCUnrestricted Upload of File with Dangerous Type in inventree/inventree
- CVE-2022-21121 PoCImproper Neutralization of Formula Elements in a CSV File in inventree/inventree
- CVE-2022-21131 PoCCross-site Scripting (XSS) - Stored in inventree/inventree
- CVE-2022-21141 PoCData Tables Generator by Supsystic < 1.10.20 - Admin+ Stored Cross-Site Scripting
- CVE-2022-21151 PoCPopup Anything < 2.1.7 - Reflected Cross-Site Scripting
- CVE-2022-21161 PoCElementor Contact Form DB < 1.8.0 - Reflected Cross-Site Scripting
- CVE-2022-21181 PoC404s < 3.5.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-21221 PoCDOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which…
- CVE-2022-21231 PoCWP Opt-in <= 1.4.1 - Arbitrary Settings Update via CSRF
- CVE-2022-21241 PoCBuffer Over-read in vim/vim
- CVE-2022-21251 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-21261 PoCOut-of-bounds Read in vim/vim
- CVE-2022-21281 PoCUnrestricted Upload of File with Dangerous Type in polonel/trudesk
- CVE-2022-21291 PoCOut-of-bounds Write in vim/vim
- CVE-2022-21302 PoCsCross-site Scripting (XSS) - Reflected in microweber/microweber
- CVE-2022-21331 PoCOAuth Single Sign On < 6.22.6 - Authentication Bypass
- CVE-2022-21341 PoCAllocation of Resources Without Limits or Throttling in inventree/inventree
- CVE-2022-21432 PoCsAdvantech iView
- CVE-2022-21441 PoCJquery Validation For Contact Form 7 < 5.3 - Arbitrary Options Update via CSRF
- CVE-2022-21461 PoCImport CSV Files <= 1.0 - Reflected Cross-Site Scripting
- CVE-2022-21481 PoCLinkedIn Company Updates <= 1.5.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-21491 PoCVery Simple Breadcrumb <= 1.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-21511 PoCBest Contact Management Software <= 3.7.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-21521 PoCDuplicate Page and Post Plugin < 2.8 - Admin+ Stored Cross-Site Scripting
- CVE-2022-21531 PoCA flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write…
- CVE-2022-21671 PoCNewspaper < 12 - Reflected Cross-Site Scripting
- CVE-2022-21682 PoCsDownload Manager < 3.2.44 - Reflected Cross-Site Scripting
- CVE-2022-21691 PoCLoading Page with Loading Screen < 1.0.83 - Admin+ Stored Cross-Site Scripting
- CVE-2022-21701 PoCMicrosoft Advertising Universal Event Tracking < 1.0.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-21711 PoCProgressive License <= 1.1.0 - CSRF to Stored XSS
- CVE-2022-21721 PoCLinkWorth Plugin < 3.3.4 - Arbitrary Setting Update via CSRF
- CVE-2022-21731 PoCAdvanced Database Cleaner < 3.1.1 - Reflected Cross-Site Scripting
- CVE-2022-21742 PoCsCross-site Scripting (XSS) - Reflected in microweber/microweber
- CVE-2022-21751 PoCBuffer Over-read in vim/vim
- CVE-2022-21801 PoCGREYD.SUITE < 1.2.7 - Unauthenticated File Upload to RCE
- CVE-2022-21811 PoCAdvanced WordPress Reset < 1.6 - Reflected Cross-Site Scripting
- CVE-2022-21821 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-21831 PoCOut-of-bounds Read in vim/vim
- CVE-2022-21841 PoCCAPTCHA 4WP < 7.1.0 - Local File Inclusion via CSRF
- CVE-2022-21853 PoCsA critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1…
- CVE-2022-21861 PoCSimple Post Notes < 1.7.6 - Admin+ Stored Cross-Site Scripting
- CVE-2022-21872 PoCsContact Form 7 Captcha < 0.1.2 - Reflected Cross-Site Scripting
- CVE-2022-21891 PoCWP Video Lightbox < 1.9.5 - Reflected Cross-Site Scripting
- CVE-2022-21901 PoCEnvira Gallery Lite < 1.8.4.7 - Reflected Cross-Site Scripting
- CVE-2022-21941 PoCAccept Stripe Payments < 2.0.64 - Admin+ Stored Cross-Site Scripting
- CVE-2022-21981 PoCWPQA < 5.7 - Subscriber+ Private Message Disclosure via IDOR
- CVE-2022-22061 PoCOut-of-bounds Read in vim/vim
- CVE-2022-22071 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-22081 PoCNULL Pointer Dereference in vim/vim
- CVE-2022-22101 PoCOut-of-bounds Write in vim/vim
- CVE-2022-22121 PoCSourceCodester Library Management System /card/index.php unrestricted upload
- CVE-2022-22131 PoCSourceCodester Library Management System cross site scripting
- CVE-2022-22142 PoCsSourceCodester Library Management System bookdetails.php sql injection
- CVE-2022-22151 PoCGiveWP < 2.21.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-22161 PoCServer-Side Request Forgery (SSRF) in ionicabizau/parse-url
- CVE-2022-22171 PoCCross-site Scripting (XSS) - Generic in ionicabizau/parse-url
- CVE-2022-22181 PoCCross-site Scripting (XSS) - Stored in ionicabizau/parse-url
- CVE-2022-22192 PoCsUnyson < 2.7.27 - Reflected Cross-Site Scripting
- CVE-2022-22221 PoCDownload Monitor < 4.5.91 - Admin+ Arbitrary File Download
- CVE-2022-22311 PoCNULL Pointer Dereference in vim/vim
- CVE-2022-22391 PoCRequest a Quote < 2.3.9 - Admin+ Stored Cross-Site Scripting
- CVE-2022-22411 PoCFeatured Image from URL < 4.0.0 - Arbitrary Settings Update to Stored XSS via CSRF
- CVE-2022-22451 PoCCounter Box < 1.2.1 - Arbitrary Counter Activation/Deactivation via CSRF
- CVE-2022-22511 PoCImproper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to…
- CVE-2022-22521 PoCOpen Redirect in microweber/microweber
- CVE-2022-22571 PoCOut-of-bounds Read in vim/vim
- CVE-2022-22601 PoCGiveWP < 2.21.3 - DoS via CSRF
- CVE-2022-22611 PoCWPide < 3.0 - Admin+ Local File Inclusion
- CVE-2022-22622 PoCsOnline Hotel Booking System Room edit_all_room.php sql injection
- CVE-2022-22631 PoCOnline Hotel Booking System Room edit_room_cat.php sql injection
- CVE-2022-22641 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-22671 PoCMailChimp for Woocommerce < 2.7.1 - Subscriber+ SSRF
- CVE-2022-22681 PoCWP All Import < 3.6.8 - Admin+ Arbitrary File Upload
- CVE-2022-22691 PoCWebsite File Changes Monitor < 1.8.3 - Admin+ SQLi
- CVE-2022-22731 PoCSimple Membership < 4.1.3 - Membership Privilege Escalation
- CVE-2022-22742 PoCsRSA implementation bug in AVX512IFMA instructions
- CVE-2022-22751 PoCWP Edit Menu <= 1.5.0 - Arbitrary Post Deletion via CSRF
- CVE-2022-22761 PoCWP Edit Menu < 1.5.0 - Unauthenticated Arbitrary Post Deletion
- CVE-2022-22781 PoCFeatured Image from URL < 4.0.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-22791 PoCNULL Pointer Dereference in bfabiszewski/libmobi
- CVE-2022-22841 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-22851 PoCInteger Overflow or Wraparound in vim/vim
- CVE-2022-22861 PoCOut-of-bounds Read in vim/vim
- CVE-2022-22871 PoCOut-of-bounds Read in vim/vim
- CVE-2022-22881 PoCOut-of-bounds Write in vim/vim
- CVE-2022-22891 PoCUse After Free in vim/vim
- CVE-2022-22902 PoCsCross-site Scripting (XSS) - Reflected in zadam/trilium
- CVE-2022-22912 PoCsSourceCodester Hotel Management System Search search cross site scripting
- CVE-2022-22921 PoCSourceCodester Hotel Management System Room Edit Page 1 cross site scripting
- CVE-2022-22932 PoCsSourceCodester Simple Sales Management System create cross site scripting
- CVE-2022-22973 PoCsSourceCodester Clinics Patient Management System unrestricted upload
- CVE-2022-22981 PoCSourceCodester Clinics Patient Management System Login Page index.php sql injection
- CVE-2022-22991 PoCAllow SVG Files <= 1.1 - Author+ Stored Cross Site Scripting via SVG
- CVE-2022-23001 PoCCross-site Scripting (XSS) - Stored in microweber/microweber
- CVE-2022-23011 PoCBuffer Over-read in hpjansson/chafa
- CVE-2022-23041 PoCStack-based Buffer Overflow in vim/vim
- CVE-2022-23051 PoCWordPress Popup <= 1.9.3.8 - Admin+ Stored Cross-Site Scripting
- CVE-2022-23061 PoCInsufficient Session Expiration in heroiclabs/nakama
- CVE-2022-23091 PoCNULL Pointer Dereference in lxml/lxml
- CVE-2022-23111 PoCFind and Replace All < 1.3 - Reflected Cross Site Scripting
- CVE-2022-23121 PoCStudent Result or Employee Database < 1.7.5 - Stored Cross Site Scripting via CSRF
- CVE-2022-23142 PoCsVR Calendar < 2.3.2 - Unauthenticated Arbitrary Function Call
- CVE-2022-23171 PoCSimple Membership < 4.1.3 - Unauthenticated Membership Privilege Escalation
- CVE-2022-23211 PoCImproper Restriction of Excessive Authentication Attempts in heroiclabs/nakama
- CVE-2022-23251 PoCInvitation Based Registrations <= 2.2.84 - Admin+ Stored Cross-Site Scripting
- CVE-2022-23281 PoCFlexi Quote Rotator <= 0.9.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-23331 PoCHoneywell SoftMaster Uncontrolled Search Path Element
- CVE-2022-23341 PoCSofting Secure Integration Server Uncontrolled Search Path Element
- CVE-2022-23391 PoCServer-Side Request Forgery (SSRF) in nocodb/nocodb
- CVE-2022-23402 PoCsW-DALIL <= 2.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-23412 PoCsSimple Page Transition <= 1.4.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-23421 PoCCross-site Scripting (XSS) - Stored in outline/outline
- CVE-2022-23431 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-23441 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-23451 PoCUse After Free in vim/vim
- CVE-2022-23501 PoCDisable User Login <= 1.0.1 - Unauthenticated Settings Update
- CVE-2022-23511 PoCPost SMTP < 2.1.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-23521 PoCPost SMTP < 2.1.7 - Admin+ Blind SSRF
- CVE-2022-23531 PoCCross-Site Request Forgery (CSRF) in microweber/microweber
- CVE-2022-23541 PoCWP-DBManager < 2.80.8 - Admin+ Remote Command Execution
- CVE-2022-23551 PoCEasy Username Updater < 1.0.5 - Arbitrary Username Update via CSRF
- CVE-2022-23561 PoCUser Private Files < 1.1.3 - Subscriber+ Arbitrary File Upload
- CVE-2022-23571 PoCWSM Downloader <= 1.4.0 - Unauthenticated Arbitrary File Download
- CVE-2022-23611 PoCSocial Chat < 6.0.5 - Admin+ Stored Cross-Site Scripting
- CVE-2022-23621 PoCDownload Manager < 3.2.50 - Bypass IP Address Blocking Restriction
- CVE-2022-23631 PoCSourceCodester Simple Parking Management System cross site scripting
- CVE-2022-23641 PoCSourceCodester Simple Parking Management System category cross site scripting
- CVE-2022-23671 PoCWSM Downloader <= 1.4.0 - Domain Name Restriction Bypass
- CVE-2022-23681 PoCAuthentication Bypass by Spoofing in microweber/microweber
- CVE-2022-23691 PoCYaySMTP < 2.2.1 - Subscriber+ Logs Disclosure
- CVE-2022-23701 PoCYaySMTP < 2.2.1 - Subscriber+ SMTP Credentials Leak
- CVE-2022-23711 PoCYaySMTP < 2.2.1 - Subscriber+ Stored Cross-Site Scripting
- CVE-2022-23721 PoCYaySMTP < 2.2.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-23732 PoCsSimply Schedule Appointments < 1.5.7.7 - Unauthenticated Email Address Disclosure
- CVE-2022-23741 PoCSimply Schedule Appointments < 1.5.7.7 - Admin+ Stored Cross-Site Scripting
- CVE-2022-23751 PoCWP Sticky Button < 1.4.1 - Unauthenticated Arbitrary Settings Update to Stored XSS
- CVE-2022-23762 PoCsDirectorist < 7.3.1 - Unauthenticated Email Address Disclosure
- CVE-2022-23771 PoCDirectorist < 7.3.0 - Subscriber+ Arbitrary E-mail Sending
- CVE-2022-23781 PoCEasy Student Results <= 2.2.8 - Reflected Cross-Site Scripting
- CVE-2022-23792 PoCsEasy Student Results <= 2.2.8 - Sensitive Information Disclosure via REST API
- CVE-2022-23811 PoCE Unlocked - Student Result <= 1.0.4 - Arbitrary File Upload via CSRF
- CVE-2022-23821 PoCProduct Slider for WooCommerce < 2.5.7 - Subscriber+ Arbitrary Options Deletion
- CVE-2022-23832 PoCsFeed Them Social < 3.0.1 - Reflected Cross-Site Scripting
- CVE-2022-23841 PoCDigital Publications by Supsystic < 1.7.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-23861 PoCCrowdsignal Polls & Ratings < 3.0.8 - Reflected Cross-Site Scripting
- CVE-2022-23871 PoCEasy Digital Downloads < 3.0 - Arbitrary Post Deletion via CSRF
- CVE-2022-23881 PoCWP Coder < 2.5.3 - Code Deletion via CSRF
- CVE-2022-23891 PoCAutomations By Autonami < 2.1.2 - Subscriber+ Automation Creation
- CVE-2022-23911 PoCInspiro Pro < 7.2.3 - Contributor+ Stored Cross-Site Scripting
- CVE-2022-23921 PoCLana Downloads Manager < 1.8.0 - Contributor+ Arbitrary File Download
- CVE-2022-23951 PoCweForms < 1.6.14 - Admin+ Stored Cross-Site Scripting
- CVE-2022-23962 PoCsSourceCodester Simple e-Learning System claire_blake cross site scripting
- CVE-2022-23981 PoCWP Comments Fields < 4.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-24001 PoCExternal Control of File Name or Path in dompdf/dompdf
- CVE-2022-24041 PoCWP Popup Builder < 1.2.9 - Reflected Cross-Site Scripting
- CVE-2022-24051 PoCWP Popup Builder < 1.3.0 - Subscriber+ Arbitrary Popup Deletion
- CVE-2022-24071 PoCWP phpMyAdmin < 5.2.0.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-24091 PoCRough Chart <= 1.0.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-24101 PoCmTouch Quiz <= 3.1.3 - Admin+ Stored Cross Site Scripting
- CVE-2022-24111 PoCAuto More Tag <= 4.0.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-24121 PoCBetter Tag Cloud <= 0.99.5 - Admin+ Stored Cross-Site Scripting
- CVE-2022-24131 PoCSlide Anything < 2.3.47 - Author+ Cross Site Scripting in slide title
- CVE-2022-24148 PoCsAccess to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker…
- CVE-2022-24181 PoCURVE Web Manager img_upload.php unrestricted upload
- CVE-2022-24191 PoCURVE Web Manager upload.php unrestricted upload
- CVE-2022-24201 PoCURVE Web Manager uploader.php unrestricted upload
- CVE-2022-24231 PoCDW Promobar <= 1.0.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-24241 PoCGoogle Maps Anywhere <= 1.2.6.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-24251 PoCWP DS Blog Map <= 3.1.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-24261 PoCThinkific Uploader <= 1.0.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-24411 PoCImageMagick Engine <= 1.7.5 - Cross-Site Request Forgery to Remote Command Execution
- CVE-2022-24481 PoCreSmush.it Image Optimizer < 0.4.6 - Admin+ Cross-Site Scripting
- CVE-2022-24491 PoCreSmush.it Image Optimizer < 0.4.7 - Multiple CSRF
- CVE-2022-24501 PoCreSmush.it Image Optimizer < 0.4.4 - Subscriber+ AJAX Calls
- CVE-2022-24531 PoCUse After Free in gpac/gpac
- CVE-2022-24541 PoCInteger Overflow or Wraparound in gpac/gpac
- CVE-2022-24601 PoCWPDating < 7.4.0 - Multiple Unauthenticated SQLi
- CVE-2022-24613 PoCsTransposh WordPress Translation <= 1.0.9.6 - Unauthorized Settings Change
- CVE-2022-24622 PoCsTransposh WordPress Translation <= 1.0.9.6 - Sensitive Information Disclosure
- CVE-2022-24661 PoCIt was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.
- CVE-2022-24672 PoCsSourceCodester Garage Management System login.php sql injection
- CVE-2022-24681 PoCSourceCodester Garage Management System editbrand.php sql injection
- CVE-2022-24701 PoCCross-site Scripting (XSS) - Reflected in microweber/microweber
- CVE-2022-24732 PoCsWP-UserOnline <= 2.87.6 - Authenticated (Admin+) Stored Cross-Site Scripting
- CVE-2022-24761 PoCA null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL…
- CVE-2022-24863 PoCsWAVLINK WN535K2/WN535K3 os command injection
- CVE-2022-24874 PoCsWAVLINK WN535K2/WN535K3 nightled.cgi os command injection
- CVE-2022-24883 PoCsWAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection
- CVE-2022-24891 PoCSourceCodester Simple E-Learning System classRoom.php sql injection
- CVE-2022-24901 PoCSourceCodester Simple E-Learning System search.php sql injection
- CVE-2022-24911 PoCSourceCodester Library Management System lab.php sql injection
- CVE-2022-24922 PoCsSourceCodester Library Management System index.php sql injection
- CVE-2022-24941 PoCCross-site Scripting (XSS) - Stored in openemr/openemr
- CVE-2022-24951 PoCCross-site Scripting (XSS) - Stored in microweber/microweber
- CVE-2022-25031 PoCLinux Kernel LoadPin bypass via dm-verity table reload
- CVE-2022-25141 PoCCross-site Scripting (XSS) - Reflected in beancount/fava
- CVE-2022-25151 PoCSimple Banner <= 2.11.0 - Authenticated Stored Cross-Site Scripting
- CVE-2022-25221 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-25231 PoCCross-site Scripting (XSS) - Reflected in beancount/fava
- CVE-2022-25321 PoCFeed Them Social < 3.0.1 - Reflected Cross-Site Scripting
- CVE-2022-25352 PoCsSearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title Disclosure
- CVE-2022-25363 PoCsTransposh WordPress Translation <= 1.0.9.6 - Authorization Bypass
- CVE-2022-25371 PoCWooCommerce PDF Invoices & Packing Slips < 3.0.1 - Reflected Cross-Site Scripting
- CVE-2022-25381 PoCWP Hide & Security Enhancer < 1.8 - Reflected Cross-Site Scripting
- CVE-2022-25431 PoCVisual Portfolio < 2.18.0 - Unauthenticated CSS Injection
- CVE-2022-25442 PoCsNinja Job Board < 1.3.3 - Resume Disclosure via Directory Listing
- CVE-2022-25463 PoCsAll-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS
- CVE-2022-25491 PoCNULL Pointer Dereference in gpac/gpac
- CVE-2022-25501 PoCOS Command Injection in hestiacp/hestiacp
- CVE-2022-25514 PoCsDuplicator < 1.4.7 - Unauthenticated Backup Download
- CVE-2022-25524 PoCsDuplicator < 1.4.7.1 - Unauthenticated System Information Disclosure
- CVE-2022-25541 PoCEnable Media Replace < 4.0.0 - Admin+ Path Traversal
- CVE-2022-25551 PoCYotpo Reviews for WooCommerce <= 2.0.4 - Arbitrary Settings Update via CSRF
- CVE-2022-25561 PoCMailChimp for Woocommerce < 2.7.2 - Admin+ SSRF
- CVE-2022-25571 PoCWordPress Team Members Showcase < 4.1.2 - Subscriber+ Arbitrary File Read and Deletion
- CVE-2022-25581 PoCSimple Job Board < 2.10.0 - Resume Disclosure via Directory Listing
- CVE-2022-25591 PoCFluent Support < 1.5.8 - Admin+ SQLi
- CVE-2022-25631 PoCTutor LMS < 2.0.10 - Admin+ Stored Cross-Site Scripting
- CVE-2022-25641 PoCPrototype Pollution in automattic/mongoose
- CVE-2022-25651 PoCBest Payments Plugin for WP < 4.2.1 - Unauthenticated Stored Cross-Site Scripting
- CVE-2022-25671 PoCForm Builder CP < 1.2.32 - Admin+ Stored Cross-Site Scripting
- CVE-2022-25711 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-25741 PoCMeks Easy Social Share < 1.2.8 - Admin+ Stored Cross-Site Scripting
- CVE-2022-25751 PoCWBW Currency Switcher for WooCommerce < 1.6.6 - Admin+ Stored XSS
- CVE-2022-25771 PoCSourceCodester Garage Management System edituser.php sql injection
- CVE-2022-25782 PoCsSourceCodester Garage Management System createUser.php access control
- CVE-2022-25801 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-25811 PoCOut-of-bounds Read in vim/vim
- CVE-2022-25853 PoCsIt was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a…
- CVE-2022-25868 PoCsKEVIt was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once…
- CVE-2022-25888 PoCsIt was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before…
- CVE-2022-25891 PoCCross-site Scripting (XSS) - Reflected in beancount/fava
- CVE-2022-25912 PoCsTEM FLEX-1085 reboot denial of service
- CVE-2022-25931 PoCBetter Search and Replace < 1.4.1 - Admin+ SQLi
- CVE-2022-25941 PoCAdvanced Custom Fields 5.0-5.12.2 - Unauthenticated File Upload
- CVE-2022-25951 PoCImproper Authorization in kromitgmbh/titra
- CVE-2022-25961 PoCInefficient Regular Expression Complexity in node-fetch/node-fetch
- CVE-2022-25971 PoCVisual Portfolio < 2.19.0 - Contributor+ CSS Injection
- CVE-2022-25981 PoCOut-of-bounds Write to API in vim/vim
- CVE-2022-25992 PoCsAnti-Malware Security and Brute-Force Firewall < 4.21.83 - Reflected Cross-Site Scripting
- CVE-2022-26024 PoCsio_uring UAF, Unix SCM garbage collection
- CVE-2022-26261 PoCIncorrect Privilege Assignment in hestiacp/hestiacp
- CVE-2022-26272 PoCsNewspaper < 12 - Reflected Cross-Site Scripting
- CVE-2022-26281 PoCDSGVO All in one for WP < 4.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-26291 PoCTop Bar < 3.0.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-26311 PoCImproper Access Control in tooljet/tooljet
- CVE-2022-26331 PoCThe All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the…
- CVE-2022-26351 PoCAutoptimize < 3.1.1 - Admin+ Stored Cross Site Scripting
- CVE-2022-26361 PoCCode Injection in hestiacp/hestiacp
- CVE-2022-26381 PoCExport All URLs < 4.4 - Admin+ Arbitrary System File Removal
- CVE-2022-26393 PoCsAn integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and…
- CVE-2022-26501 PoCImproper Restriction of Excessive Authentication Attempts in wger-project/wger
- CVE-2022-26512 PoCsAuthentication Bypass by Primary Weakness in bookwyrm-social/bookwyrm
- CVE-2022-26521 PoCUse of Externally-Controlled Format String in umlaeute/v4l2loopback
- CVE-2022-26531 PoCPath Traversal in plankanban/planka
- CVE-2022-26541 PoCClassima < 2.1.11 - Reflected Cross-Site Scripting
- CVE-2022-26551 PoCClassified Listing Pro < 2.0.20 - Reflected Cross-Site Scripting
- CVE-2022-26571 PoCMultivendor Marketplace Solution for WooCommerce < 3.8.12 - Unauthorised AJAX Calls
- CVE-2022-26581 PoCWP Spell Check < 9.13 - Admin+ Stored Cross-Site Scripting
- CVE-2022-26631 PoCAn issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message.…
- CVE-2022-26661 PoCSourceCodester Loan Management System login.php sql injection
- CVE-2022-26691 PoCWP Taxonomy Import <= 1.0.4 - Reflected Cross-Site Scripting
- CVE-2022-26771 PoCSourceCodester Apartment Visitor Management System index.php sql injection
- CVE-2022-26831 PoCSourceCodester Simple Food Ordering System login.php cross site scripting
- CVE-2022-26841 PoCSourceCodester Apartment Visitor Management System manage-apartment.php cross site scripting
- CVE-2022-26981 PoCSourceCodester Simple E-Learning System search.php sql injection
- CVE-2022-27061 PoCSourceCodester Online Class and Exam Scheduling System class_sched.php sql injection
- CVE-2022-27071 PoCSourceCodester Online Class and Exam Scheduling System faculty_sched.php sql injection
- CVE-2022-27091 PoCFloat to Top Button <= 2.3.6 - Admin+ Stored Cross-Site Scripting
- CVE-2022-27101 PoCScroll To Top < 1.4.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-27111 PoCWP All Import < 3.6.9 - Admin+ Directory traversal via file upload
- CVE-2022-27131 PoCInsufficient Session Expiration in cockpit-hq/cockpit
- CVE-2022-27231 PoCSourceCodester Employee Management System eprocess.php sql injection
- CVE-2022-27241 PoCSourceCodester Employee Management System aprocess.php sql injection
- CVE-2022-27291 PoCCross-site Scripting (XSS) - DOM in openemr/openemr
- CVE-2022-27301 PoCAuthorization Bypass Through User-Controlled Key in openemr/openemr
- CVE-2022-27311 PoCCross-site Scripting (XSS) - Reflected in openemr/openemr
- CVE-2022-27321 PoCMissing Authorization in openemr/openemr
- CVE-2022-27332 PoCsCross-site Scripting (XSS) - Reflected in openemr/openemr
- CVE-2022-27341 PoCImproper Restriction of Rendered UI Layers or Frames in openemr/openemr
- CVE-2022-27371 PoCWP STAGING < 2.9.18 - Admin+ Stored Cross-Site Scripting
- CVE-2022-27531 PoCKetchup Restaurant Reservations <= 1.0.0 - Unauthenticated Stored XSS
- CVE-2022-27541 PoCKetchup Restaurant Reservations <= 1.0.0 - Unauthenticated Blind SQLi
- CVE-2022-27562 PoCsServer-Side Request Forgery (SSRF) in kareadita/kavita
- CVE-2022-27621 PoCAdminPad < 2.2 - Note Update via CSRF
- CVE-2022-27631 PoCWP Socializer < 7.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-27651 PoCSourceCodester Company Website CMS settings improper authentication
- CVE-2022-27751 PoCFast Flow < 1.2.13 - Admin+ Stored Cross-Site Scripting
- CVE-2022-27771 PoCCross-site Scripting (XSS) - Stored in microweber/microweber
- CVE-2022-27951 PoCProcessing large delegations may severely degrade resolver performance
- CVE-2022-27961 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-27981 PoCAffiliates Manager < 2.9.14 - Affiliate CSV Injection
- CVE-2022-27991 PoCAffiliates Manager < 2.9.14 - Admin+ Stored Cross-Site Scripting
- CVE-2022-28001 PoCSourceCodester Gym Management System clickjacking
- CVE-2022-28141 PoCSourceCodester Simple and Nice Shopping Cart Script login.php cross site scripting
- CVE-2022-28161 PoCOut-of-bounds Read in vim/vim
- CVE-2022-28171 PoCUse After Free in vim/vim
- CVE-2022-28181 PoCImproper Removal of Sensitive Information Before Storage or Transfer in cockpit-hq/cockpit
- CVE-2022-28191 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-28201 PoCSession Fixation in namelessmc/nameless
- CVE-2022-28211 PoCMissing Critical Step in Authentication in namelessmc/nameless
- CVE-2022-28231 PoCSlider, Gallery, and Carousel by MetaSlider < 3.27.9 - Admin+ Stored Cross Site Scripting
- CVE-2022-28241 PoCAuthorization Bypass Through User-Controlled Key in openemr/openemr
- CVE-2022-28271 PoCAMI MegaRAC User Enumeration Vulnerability
- CVE-2022-28291 PoCCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm
- CVE-2022-28311 PoCA flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash…
- CVE-2022-28321 PoCA flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of…
- CVE-2022-28331 PoCEndless Infinite loop in Blender-thumnailing due to logical bugs.
- CVE-2022-28341 PoCHelpful < 4.5.26 - Information Disclosure
- CVE-2022-28391 PoCZephyr Project Manager < 3.2.55 - Unauthorised AJAX Calls To Stored XSS
- CVE-2022-28403 PoCsZephyr Project Manager < 3.2.5 - Multiple Unauthenticated SQLi
- CVE-2022-28414 PoCsCrowdStrike Falcon Uninstallation authorization
- CVE-2022-28451 PoCImproper Validation of Specified Quantity in Input in vim/vim
- CVE-2022-28462 PoCsCalendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSS
- CVE-2022-28471 PoCSourceCodester Guest Management System front.php sql injection
- CVE-2022-28491 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-28621 PoCUse After Free in vim/vim
- CVE-2022-28633 PoCsWPvivid Backup < 0.9.76 - Admin+ Arbitrary File Read
- CVE-2022-28711 PoCCross-site Scripting (XSS) - Stored in notrinos/notrinoserp
- CVE-2022-28721 PoCUnrestricted Upload of File with Dangerous Type in octoprint/octoprint
- CVE-2022-28741 PoCNULL Pointer Dereference in vim/vim
- CVE-2022-28771 PoCTitan Anti-spam & Security < 7.3.1 - Protection Bypass due to IP Spoofing
- CVE-2022-28842 PoCsA vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an…
- CVE-2022-28851 PoCCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm
- CVE-2022-28871 PoCWP Server Health Stats < 1.7.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-28881 PoCInsufficient Session Expiration in octoprint/octoprint
- CVE-2022-28891 PoCUse After Free in vim/vim
- CVE-2022-28901 PoCCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm
- CVE-2022-28911 PoCWP 2FA < 2.3.0 - Time-Based Side-Channel Attack
- CVE-2022-29011 PoCImproper Authorization in chatwoot/chatwoot
- CVE-2022-29031 PoCNinjaForms < 3.6.13 - Admin+ PHP Objection Injection
- CVE-2022-29121 PoCCraw Data <= 1.0.0 - Server Side Request Forgery
- CVE-2022-29131 PoCLogin No Captcha reCAPTCHA < 1.7 - IP Check Bypass
- CVE-2022-29211 PoCExposure of Private Personal Information to an Unauthorized Actor in notrinos/notrinoserp
- CVE-2022-29221 PoCRelative Path Traversal in dnnsoftware/dnn.platform
- CVE-2022-29231 PoCNULL Pointer Dereference in vim/vim
- CVE-2022-29241 PoCCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm
- CVE-2022-29251 PoCCross-site Scripting (XSS) - Stored in appwrite/appwrite
- CVE-2022-29261 PoCDownload Manager < 3.2.55 - Admin+ Arbitrary File/Folder Access via Path Traversal
- CVE-2022-29271 PoCWeak Password Requirements in notrinos/notrinoserp
- CVE-2022-29301 PoCUnverified Password Change in octoprint/octoprint
- CVE-2022-29412 PoCsWP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting
- CVE-2022-29431 PoCWordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Authenticated (Admin+) Arbitrary File Read
- CVE-2022-29451 PoCWordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Directory Traversal
- CVE-2022-29461 PoCUse After Free in vim/vim
- CVE-2022-29531 PoCLibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service…
- CVE-2022-29561 PoCConsoleTVs Noxen users.php cross site scripting
- CVE-2022-29571 PoCSourceCodester Simple and Nice Shopping Cart Script profile.php sql injection
- CVE-2022-29581 PoCBadgeOS < 3.7.1.3 - Subscriber+ SQLi
- CVE-2022-29651 PoCImproper Restriction of Rendered UI Layers or Frames in notrinos/notrinoserp
- CVE-2022-29801 PoCNULL Pointer Dereference in vim/vim
- CVE-2022-29811 PoCDownload Monitor < 4.5.98 - Admin+ Arbitrary File Download
- CVE-2022-29821 PoCUse After Free in vim/vim
- CVE-2022-29831 PoCSalat Times < 3.2.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-29871 PoCLdap WP Login / Active Directory Integration < 3.0.2 - Unauthenticated Settings Update to Auth Bypass
- CVE-2022-29891 PoCAn incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or…
- CVE-2022-29901 PoCAn incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or…
- CVE-2022-29925 PoCsA vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated…
- CVE-2022-29951 PoCIncorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible…
- CVE-2022-29971 PoCSession Fixation in snipe/snipe-it