CVE-2022-30000 to CVE-2022-30999
115 CVEs with public proof-of-concept exploits.
- CVE-2022-300031 PoCSourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then…
- CVE-2022-300041 PoCSourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers…
- CVE-2022-300111 PoCIn HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.
- CVE-2022-300121 PoCIn the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database…
- CVE-2022-300141 PoCLumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover…
- CVE-2022-300231 PoCTenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
- CVE-2022-300241 PoCA buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker…
- CVE-2022-300402 PoCsTenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimecfg of / bin /…
- CVE-2022-300451 PoCAn issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted…
- CVE-2022-300501 PoCGnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php.
- CVE-2022-300521 PoCIn Home Clean Service System 1.0, the password parameter is vulnerable to SQL injection attacks.
- CVE-2022-300531 PoCIn Toll Tax Management System 1.0, the id parameter appears to be vulnerable to SQL injection attacks.
- CVE-2022-300541 PoCIn Covid 19 Travel Pass Management 1.0, the code parameter is vulnerable to SQL injection attacks.
- CVE-2022-300551 PoCPrime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution.
- CVE-2022-300671 PoCGIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of…
- CVE-2022-300731 PoCWBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.
- CVE-2022-300758 PoCsIn TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution…
- CVE-2022-300762 PoCsENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000…
- CVE-2022-300781 PoCNETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93…
- CVE-2022-300791 PoCCommand injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that…
- CVE-2022-301051 PoCIn Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device,…
- CVE-2022-301112 PoCsDue to the use of an insecure algorithm for rolling codes in MCK Smartlock 1.0, allows attackers to unlock the mechanism via replay attacks.
- CVE-2022-301142 PoCsA heap-based buffer overflow in a network service in Fastweb FASTGate MediaAccess FGA2130FWB, firmware version 18.3.n.0482_FW_230_FGA2130,…
- CVE-2022-301291 PoCVisual Studio Code Remote Code Execution Vulnerability
- CVE-2022-301363 PoCsWindows Network File System Remote Code Execution Vulnerability
- CVE-2022-3019090 PoCsKEVMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
- CVE-2022-302063 PoCsWindows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-302161 PoCWindows Server Service Tampering Vulnerability
- CVE-2022-302801 PoC/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary…
- CVE-2022-302863 PoCspyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.
- CVE-2022-302921 PoCHeap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.
- CVE-2022-302931 PoCIn WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in…
- CVE-2022-303271 PoCAn issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The web interface is vulnerable to CSRF. An attacker can change the…
- CVE-2022-303301 PoCIn the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security restrictions on…
- CVE-2022-303338 PoCsKEVRARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as…
- CVE-2022-303521 PoCphpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in…
- CVE-2022-304251 PoCTenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr and traceAddr…
- CVE-2022-304261 PoCThere is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An…
- CVE-2022-304271 PoCIn ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal.
- CVE-2022-304281 PoCIn ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.
- CVE-2022-304661 PoCjoyebike Joy ebike Wolf Manufacturing year 2022 is vulnerable to Authentication Bypass by Capture-replay.
- CVE-2022-304671 PoCJoy ebike Wolf Manufacturing year 2022 is vulnerable to Denial of service, which allows remote attackers to jam the key fob request via RF.
- CVE-2022-304691 PoCIn Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman§ion=get&page=grid` leads to…
- CVE-2022-304721 PoCTenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat
- CVE-2022-304731 PoCTenda AC Series Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function form_fast_setting_wifi_set
- CVE-2022-304741 PoCTenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling…
- CVE-2022-304751 PoCTenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling…
- CVE-2022-304761 PoCTenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling…
- CVE-2022-304771 PoCTenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling…
- CVE-2022-304892 PoCsWAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.
- CVE-2022-304901 PoCBadminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
- CVE-2022-305081 PoCDedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.
- CVE-2022-305101 PoCSchool Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59.
- CVE-2022-305111 PoCSchool Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4.
- CVE-2022-305122 PoCsSchool Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.
- CVE-2022-305132 PoCsSchool Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:125
- CVE-2022-305142 PoCsSchool Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:126.
- CVE-2022-305151 PoCZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename…
- CVE-2022-305181 PoCChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2022-305192 PoCsXSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password…
- CVE-2022-305241 PoCThere is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters…
- CVE-2022-3052523 PoCsKEVA OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200…
- CVE-2022-305263 PoCsA privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG…
- CVE-2022-305411 PoCAn OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X…
- CVE-2022-305431 PoCA leftover debug code vulnerability exists in the console infct functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted…
- CVE-2022-305471 PoCA directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A…
- CVE-2022-305911 PoCquic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete…
- CVE-2022-305921 PoCliblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.
- CVE-2022-305942 PoCsThe Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions…
- CVE-2022-306001 PoCA flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
- CVE-2022-306031 PoCAn OS command injection vulnerability exists in the web interface /action/iperf functionality of Abode Systems, Inc. iota All-In-One…
- CVE-2022-306051 PoCA privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A…
- CVE-2022-306901 PoCA cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A…
- CVE-2022-307081 PoCWebmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not…
- CVE-2022-307591 PoCIn Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root…
- CVE-2022-307631 PoCJanet before 1.22.0 mishandles arrays.
- CVE-2022-307751 PoCxpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF…
- CVE-2022-307761 PoCatmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
- CVE-2022-307771 PoCParallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.
- CVE-2022-307802 PoCsLighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because…
- CVE-2022-307815 PoCsGitea before 1.16.7 does not escape git fetch remote.
- CVE-2022-307901 PoCDas U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
- CVE-2022-308521 PoCKnown v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).
- CVE-2022-308582 PoCsAn issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_file2_0
- CVE-2022-308601 PoCFUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel.
- CVE-2022-308611 PoCFUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature.
- CVE-2022-308631 PoCFUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Panel.
- CVE-2022-308742 PoCsThere is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.
- CVE-2022-308861 PoCSchool Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at…
- CVE-2022-308873 PoCsPharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component…
- CVE-2022-308981 PoCA Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's…
- CVE-2022-309031 PoCNokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site…
- CVE-2022-309091 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the CMD parameter at /goform/aspForm.
- CVE-2022-309102 PoCsH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the GO parameter at /goform/aspForm.
- CVE-2022-309121 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateWanParams parameter at /goform/aspForm.
- CVE-2022-309131 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the ipqos_set_bandwidth parameter at…
- CVE-2022-309141 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateMacClone parameter at /goform/aspForm.
- CVE-2022-309151 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateSnat parameter at /goform/aspForm.
- CVE-2022-309161 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTelnetDebug parameter at…
- CVE-2022-309171 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the AddWlanMacList parameter at /goform/aspForm.
- CVE-2022-309181 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTelnet parameter at /goform/aspForm.
- CVE-2022-309191 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Edit_BasicSSID_5G parameter at /goform/aspForm.
- CVE-2022-309201 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Edit_BasicSSID parameter at /goform/aspForm.
- CVE-2022-309211 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the SetMobileAPInfoById parameter at…
- CVE-2022-309221 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the EditWlanMacList parameter at /goform/aspForm.
- CVE-2022-309231 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTimingtimeWifiAndLed parameter at…
- CVE-2022-309241 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the SetAPWifiorLedInfoById parameter at…
- CVE-2022-309251 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the AddMacList parameter at /goform/aspForm.
- CVE-2022-309261 PoCH3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the EditMacList parameter at /goform/aspForm.
- CVE-2022-309271 PoCA SQL injection vulnerability exists in Simple Task Scheduling System 1.0 when MySQL is being used as the application database. An…
- CVE-2022-309292 PoCsMini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.
- CVE-2022-309741 PoCcompile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than…
- CVE-2022-309751 PoCIn Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.
- CVE-2022-309761 PoCGPAC 2.0.0 misuses a certain Unicode utf8_wcslen (renamed gf_utf8_wcslen) function in utils/utf.c, resulting in a heap-based buffer…
- CVE-2022-309821 PoCAn issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username.