CVE-2022-31000 to CVE-2022-31999
230 CVEs with public proof-of-concept exploits.
- CVE-2022-310001 PoCCSRF allows attacker to finalize/unfinalize order adjustments in solidus_backend
- CVE-2022-310072 PoCsPrivilege escalation from administrator in eLabFTW
- CVE-2022-310561 PoCSQL injection with _actor parameter in GLPI
- CVE-2022-310611 PoCSQL injection on login page in GLPI
- CVE-2022-310621 PoCUnauthenticated Local File Inclusion
- CVE-2022-310642 PoCsCross site scripting in username that will trigger by sending chat
- CVE-2022-311015 PoCsSQL Injection in prestashop/blockwishlist
- CVE-2022-311061 PoCPrototype Pollution in underscore.deep
- CVE-2022-311081 PoCArbitrary `CSS` injection into the generated graph affecting the container HTML in mermaid.js
- CVE-2022-311101 PoCDenial of Service (DoS) vulnerability in RSSHub
- CVE-2022-311251 PoCAuthentication Bypass in Roxy-wi
- CVE-2022-311262 PoCsUnauthenticated Remote Code Execution in Roxy-wi
- CVE-2022-311291 PoCInefficient Regular Expression Complexity in moment
- CVE-2022-311374 PoCsUnauthenticated Remote Code Execution in Roxy-WI
- CVE-2022-311381 PoCOS Command Injection in mailcow
- CVE-2022-311441 PoCPotential heap overflow in Redis
- CVE-2022-311591 PoCPartial Path Traversal in com.amazonaws:aws-java-sdk-s3
- CVE-2022-311601 PoCjQuery UI contains potential XSS vulnerability when refreshing a checkboxradio with an HTML-like initial text label
- CVE-2022-311612 PoCsRoxy-WI Vulnerable to Unauthenticated Remote Code Execution via ssl_cert Upload
- CVE-2022-311732 PoCsJuniper is vulnerable to @DOS GraphQL Nested Fragments overflow
- CVE-2022-311812 PoCsRemote code execution in prestashop
- CVE-2022-311883 PoCsServer-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
- CVE-2022-311921 PoCCross Site Scripting possible in DSpace JSPUI "Request a Copy" feature
- CVE-2022-311941 PoCPath traversal vulnerabilities in DSpace JSPUI submission upload
- CVE-2022-311951 PoCPath traversal vulnerability in Simple Archive Format package import in DSpace
- CVE-2022-311991 PoCKEVRemote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix…
- CVE-2022-312011 PoCSoftGuard Web (SGW) before 5.1.5 allows HTML injection.
- CVE-2022-312021 PoCThe export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl.
- CVE-2022-312111 PoCAn issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default.
- CVE-2022-312121 PoCAn issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. c-shquote contains…
- CVE-2022-312131 PoCAn issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malformed XML config…
- CVE-2022-312451 PoCmailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug…
- CVE-2022-312501 PoCkeylime %post scriplet allows for privilege escalation from keylime user to root
- CVE-2022-312511 PoCslurm: %post for slurm-testsuite operates as root in user owned directory
- CVE-2022-312541 PoCrmt-server-pubcloud allows to escalate from user _rmt to root
- CVE-2022-312591 PoCThe route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route…
- CVE-2022-312601 PoCIn Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a…
- CVE-2022-312624 PoCsAn exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker…
- CVE-2022-312641 PoCSolana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF…
- CVE-2022-312682 PoCsA Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or…
- CVE-2022-312695 PoCsNortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's…
- CVE-2022-312821 PoCBento4 MP4Dump v1.2 was discovered to contain a segmentation violation via an unknown address at /Source/C++/Core/Ap4DataBuffer.cpp:175.
- CVE-2022-312851 PoCAn issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h.
- CVE-2022-312871 PoCAn issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.
- CVE-2022-312901 PoCA cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or…
- CVE-2022-312941 PoCAn issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update…
- CVE-2022-312951 PoCAn issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.
- CVE-2022-312961 PoCOnline Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.
- CVE-2022-312981 PoCA cross-site scripting vulnerability in the ads comment section of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML…
- CVE-2022-312992 PoCsHaraj v3.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the User Upgrade Form.
- CVE-2022-313001 PoCA cross-site scripting vulnerability in the DM Section component of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML…
- CVE-2022-313011 PoCHaraj v3.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Post Ads component.
- CVE-2022-313061 PoCNginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c.
- CVE-2022-313071 PoCNginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.c.
- CVE-2022-313081 PoCA vulnerability in live_mfg.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.191012 allows attackers to obtain sensitive router information via…
- CVE-2022-313091 PoCA vulnerability in live_check.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to obtain sensitive router information…
- CVE-2022-313111 PoCAn issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a crafted POST request.
- CVE-2022-313252 PoCsThere is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.
- CVE-2022-313611 PoCDocebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects…
- CVE-2022-313621 PoCDocebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only…
- CVE-2022-313661 PoCAn arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to…
- CVE-2022-313671 PoCStrapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.
- CVE-2022-313731 PoCSolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php.
- CVE-2022-313821 PoCDirectory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in…
- CVE-2022-313831 PoCDirectory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
- CVE-2022-313841 PoCDirectory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
- CVE-2022-313861 PoCA Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make…
- CVE-2022-313901 PoCJizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in…
- CVE-2022-313931 PoCJizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in…
- CVE-2022-313951 PoCAlgo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web…
- CVE-2022-313981 PoCA cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web…
- CVE-2022-314001 PoCA cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web…
- CVE-2022-314022 PoCsITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.
- CVE-2022-314031 PoCITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.
- CVE-2022-314151 PoCOnline Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php.
- CVE-2022-314461 PoCTenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac…
- CVE-2022-314641 PoCInsecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing the service…
- CVE-2022-314691 PoCOX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
- CVE-2022-314703 PoCsAn XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before…
- CVE-2022-314742 PoCsWordPress BackupBuddy Plugin 8.5.8.0-8.7.4.1 is vulnerable to Directory Traversal
- CVE-2022-314911 PoCVoltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote…
- CVE-2022-314921 PoCCross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username.
- CVE-2022-314931 PoCLibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.
- CVE-2022-314941 PoCLibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.
- CVE-2022-314951 PoCLibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.
- CVE-2022-314961 PoCLibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.
- CVE-2022-314981 PoCLibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.
- CVE-2022-314994 PoCsNortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this…
- CVE-2022-315011 PoCThe ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315021 PoCThe operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315031 PoCThe orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315041 PoCThe ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask…
- CVE-2022-315051 PoCThe cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function…
- CVE-2022-315061 PoCThe cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315072 PoCsThe ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315081 PoCThe idayrus/evoting repository before 2022-05-08 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315091 PoCThe iedadata/usap-dc-website repository through 1.0.1 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315101 PoCThe sergeKashkin/Simple-RAT repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315111 PoCThe AFDudley/equanimity repository through 2014-04-23 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315121 PoCThe Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315131 PoCThe BolunHan/Krypton repository through 2021-06-03 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315141 PoCThe Caoyongqi912/Fan_Platform repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function…
- CVE-2022-315151 PoCThe Delor4/CarceresBE repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- CVE-2022-315161 PoCThe Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315171 PoCThe HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315181 PoCThe JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the…
- CVE-2022-315191 PoCThe Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315201 PoCThe Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315211 PoCThe Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315221 PoCThe NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315231 PoCThe PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315241 PoCThe PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function…
- CVE-2022-315251 PoCThe SummaLabs/DLS repository through 0.1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- CVE-2022-315261 PoCThe ThundeRatz/ThunderDocs repository through 2020-05-01 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315271 PoCThe Wildog/flask-file-server repository through 2020-02-20 on GitHub allows absolute path traversal because the Flask send_file function…
- CVE-2022-315281 PoCThe bonn-activity-maps/bam_annotation_tool repository through 2021-08-31 on GitHub allows absolute path traversal because the Flask…
- CVE-2022-315291 PoCThe cinemaproject/monorepo repository through 2021-03-03 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315301 PoCThe csm-aut/csm repository through 3.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- CVE-2022-315311 PoCThe dainst/cilantro repository through 0.0.4 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- CVE-2022-315321 PoCThe dankolbman/travel_blahg repository through 2016-01-16 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315331 PoCThe decentraminds/umbral repository through 2020-01-15 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315341 PoCThe echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315351 PoCThe freefood89/Fishtank repository through 2015-06-24 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315361 PoCThe jaygarza1982/ytdl-sync repository through 2021-01-02 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315371 PoCThe jmcginty15/Solar-system-simulator repository through 2021-07-26 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315381 PoCThe joaopedro-fg/mp-m08-interface repository through 2020-12-10 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315391 PoCThe kotekan/kotekan repository through 2021.11 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315401 PoCThe kumardeepak/hin-eng-preprocessing repository through 2019-07-16 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315411 PoCThe lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315421 PoCThe mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315431 PoCThe maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315441 PoCThe meerstein/rbtm repository through 1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- CVE-2022-315451 PoCThe ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315461 PoCThe nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315471 PoCThe noamezekiel/sphere repository through 2020-05-31 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315481 PoCThe nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315492 PoCsThe olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function…
- CVE-2022-315501 PoCThe olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315511 PoCThe pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function…
- CVE-2022-315521 PoCThe project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315531 PoCThe rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask send_file function…
- CVE-2022-315541 PoCThe rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal because the Flask…
- CVE-2022-315551 PoCThe romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315561 PoCThe rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315671 PoCThe DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- CVE-2022-315681 PoCThe Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315711 PoCThe akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask…
- CVE-2022-315721 PoCThe ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315731 PoCThe chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315741 PoCThe deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function…
- CVE-2022-315751 PoCThe duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315761 PoCThe heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315781 PoCThe piaoyunsoft/bt_lnmp repository through 2019-10-10 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315801 PoCThe sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315812 PoCsThe scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315821 PoCThe shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-315831 PoCThe sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315841 PoCThe stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_file function is used…
- CVE-2022-315851 PoCThe umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315861 PoCThe unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315871 PoCThe yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file…
- CVE-2022-315881 PoCThe zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is…
- CVE-2022-316201 PoCIn libjpeg before 1.64, BitStream<false>::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related…
- CVE-2022-316261 PoCmysqlnd/pdo password buffer overflow
- CVE-2022-316291 PoC$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities
- CVE-2022-316302 PoCsOOB read due to insufficient input validation in imageloadfont()
- CVE-2022-316501 PoCIn SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.
- CVE-2022-316511 PoCIn SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.
- CVE-2022-316561 PoCVMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local…
- CVE-2022-316601 PoCVMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor…
- CVE-2022-316721 PoCVMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can…
- CVE-2022-316741 PoCVMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can…
- CVE-2022-316751 PoCVMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be…
- CVE-2022-316781 PoCVMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may…
- CVE-2022-316801 PoCThe vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with…
- CVE-2022-316831 PoCConcourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with…
- CVE-2022-316912 PoCsSpring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor,…
- CVE-2022-316923 PoCsSpring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or…
- CVE-2022-317044 PoCsThe vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into…
- CVE-2022-317052 PoCsVMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor…
- CVE-2022-317064 PoCsThe vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the…
- CVE-2022-317114 PoCsVMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and…
- CVE-2022-317492 PoCsAuthenticated arbitrary file read/write in WatchGuard Fireware OS
- CVE-2022-317831 PoCLiblouis 3.21.0 has an out-of-bounds write in compileRule in compileTranslationTable.c, as demonstrated by lou_trace.
- CVE-2022-317861 PoCIdeaLMS 2022 allows reflected Cross Site Scripting (XSS) via the IdeaLMS/Class/Assessment/ PATH_INFO.
- CVE-2022-317872 PoCsIdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO
- CVE-2022-317882 PoCsIdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname.
- CVE-2022-317901 PoCWatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication server settings by…
- CVE-2022-317935 PoCsdo_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single…
- CVE-2022-317941 PoCAn issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in…
- CVE-2022-317951 PoCAn issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in…
- CVE-2022-317982 PoCsNortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID)…
- CVE-2022-318132 PoCsmod_proxy X-Forwarded-For dropped by hop-by-hop mechanism
- CVE-2022-3181412 PoCspfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP…
- CVE-2022-318271 PoCMonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php.
- CVE-2022-318301 PoCKity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.
- CVE-2022-318361 PoCThe leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.
- CVE-2022-318452 PoCsA vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via…
- CVE-2022-318462 PoCsA vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via…
- CVE-2022-318472 PoCsA vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router…
- CVE-2022-318545 PoCsCodoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.
- CVE-2022-318561 PoCNewsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.
- CVE-2022-318601 PoCAn issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.
- CVE-2022-318611 PoCCross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.
- CVE-2022-318731 PoCTrendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an XSS vulnerability via the prefix parameter in /admin/general.cgi.
- CVE-2022-318741 PoCASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.
- CVE-2022-318751 PoCTrendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnerability via the proname parameter in /admin/scheprofile.cgi
- CVE-2022-318761 PoCnetgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users…
- CVE-2022-318771 PoCAn issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.
- CVE-2022-318792 PoCsOnline Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter.
- CVE-2022-318841 PoCMarval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other users API Keys…
- CVE-2022-318852 PoCsMarval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
- CVE-2022-318863 PoCsMarval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a…
- CVE-2022-318871 PoCMarval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the…
- CVE-2022-318892 PoCsCross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit…
- CVE-2022-318902 PoCsSQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae…
- CVE-2022-318972 PoCsSourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.
- CVE-2022-318982 PoCsgl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the…
- CVE-2022-319011 PoCBuffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two…
- CVE-2022-319021 PoCNotepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().
- CVE-2022-319741 PoCOnline Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=reports&date=.
- CVE-2022-319751 PoCOnline Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=user/manage_user&id=.
- CVE-2022-319761 PoCOnline Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request.
- CVE-2022-319771 PoCOnline Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.
- CVE-2022-319781 PoCOnline Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.
- CVE-2022-319801 PoCOnline Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/manage_team&id=.
- CVE-2022-319811 PoCOnline Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/view_team&id=.
- CVE-2022-319821 PoCOnline Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/view_request&id=.
- CVE-2022-319832 PoCsOnline Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/manage_request&id=.
- CVE-2022-319841 PoCOnline Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=.