CVE-2022-32000 to CVE-2022-32999
143 CVEs with public proof-of-concept exploits.
- CVE-2022-320071 PoCComplete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.
- CVE-2022-320131 PoCComplete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/category/index.php?view=edit&id=.
- CVE-2022-320151 PoCComplete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=.
- CVE-2022-320181 PoCComplete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.
- CVE-2022-320221 PoCCar Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login.
- CVE-2022-320241 PoCCar Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.
- CVE-2022-320251 PoCCar Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.
- CVE-2022-320261 PoCCar Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=.
- CVE-2022-320281 PoCCar Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.
- CVE-2022-320301 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetQosBand.
- CVE-2022-320311 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetRouteStatic.
- CVE-2022-320321 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the function formAddMacfilterRule.
- CVE-2022-320331 PoCTenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the function formSetVirtualSer.
- CVE-2022-320341 PoCTenda M3 V1.0.0.12 was discovered to contain a stack overflow via the items parameter in the function formdelMasteraclist.
- CVE-2022-320351 PoCTenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formMasterMng.
- CVE-2022-320361 PoCTenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters…
- CVE-2022-320371 PoCTenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAPCfg.
- CVE-2022-320391 PoCTenda M3 V1.0.0.12 was discovered to contain a stack overflow via the listN parameter in the function fromDhcpListClient.
- CVE-2022-320401 PoCTenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetCfm.
- CVE-2022-320411 PoCTenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnalyseData.
- CVE-2022-320431 PoCTenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo.
- CVE-2022-320441 PoCTOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the password parameter in the function FUN_00413f80.
- CVE-2022-320451 PoCTOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00413be4.
- CVE-2022-320461 PoCTOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_0041880c.
- CVE-2022-320471 PoCTOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00412ef4.
- CVE-2022-320481 PoCTOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the command parameter in the function FUN_0041cc88.
- CVE-2022-320491 PoCTOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the url parameter in the function FUN_00418540.
- CVE-2022-320501 PoCTOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.
- CVE-2022-320511 PoCTOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc, week, sTime, eTime parameters in the function…
- CVE-2022-320521 PoCTOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_004137a4.
- CVE-2022-320531 PoCTOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.
- CVE-2022-320551 PoCInout Homestay v2.2 was discovered to contain a SQL injection vulnerability via the guests parameter at /index.php?page=search/rentals.
- CVE-2022-320561 PoCOnline Accreditation Management v1.0 was discovered to contain a SQL injection vulnerability via the USERNAME parameter at process.php.
- CVE-2022-320602 PoCsAn arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary…
- CVE-2022-320611 PoCAn arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to…
- CVE-2022-320652 PoCsAn arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary…
- CVE-2022-320741 PoCA stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit…
- CVE-2022-320811 PoCMariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at…
- CVE-2022-320851 PoCMariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.
- CVE-2022-320861 PoCMariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.
- CVE-2022-320881 PoCMariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component…
- CVE-2022-320891 PoCMariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.
- CVE-2022-320941 PoCHospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.
- CVE-2022-321142 PoCsAn unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a…
- CVE-2022-321151 PoCAn issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file.
- CVE-2022-321181 PoCArox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in…
- CVE-2022-321191 PoCArox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at…
- CVE-2022-321591 PoCOpenlibrary - Stored XSS
- CVE-2022-321671 PoCCloudreve - Stored XSS
- CVE-2022-321691 PoCbytebase - Improper Authorization
- CVE-2022-321702 PoCsbytebase - Improper Authorization
- CVE-2022-321731 PoCOrchardCore - HTML Injection
- CVE-2022-321741 PoCGogs - XSS
- CVE-2022-321751 PoCAdGuardHome - CSRF
- CVE-2022-321761 PoCGin-vue-admin - Unrestricted File Upload
- CVE-2022-321771 PoCGin-vue-admin - Unrestricted File Upload
- CVE-2022-321951 PoCOpen edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
- CVE-2022-321991 PoCdb_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traversal sequence in…
- CVE-2022-322001 PoClibdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c.
- CVE-2022-322011 PoCIn libjpeg 1.63, there is a NULL pointer dereference in Component::SubXOf in component.hpp.
- CVE-2022-322021 PoCIn libjpeg 1.63, there is a NULL pointer dereference in LineBuffer::FetchRegion in linebuffer.cpp.
- CVE-2022-322231 PoCNode.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be…
- CVE-2022-322241 PoCA possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and…
- CVE-2022-322301 PoCSMBv3 FileNormalizedNameInformation NULL Pointer Dereference
- CVE-2022-322509 PoCsnet/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate…
- CVE-2022-322692 PoCsIn Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet…
- CVE-2022-322702 PoCsIn Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to…
- CVE-2022-322712 PoCsIn Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by…
- CVE-2022-322721 PoCOPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have…
- CVE-2022-322741 PoCThe Transition Scheduler add-on 6.5.0 for Atlassian Jira is prone to stored XSS via the project name to the creation function.
- CVE-2022-322752 PoCsGrafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /..…
- CVE-2022-322762 PoCsGrafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI…
- CVE-2022-322821 PoCAn improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a…
- CVE-2022-322871 PoCApache UIMA prior to 3.3.1 has a path traversal vulnerability when extracting (PEAR) archives
- CVE-2022-322981 PoCToybox v0.8.7 was discovered to contain a NULL pointer dereference via the component httpd.c. This vulnerability can lead to a Denial of…
- CVE-2022-323101 PoCAn access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request…
- CVE-2022-323111 PoCIngredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2022-323171 PoCThe MPlayer Project v1.5 was discovered to contain a heap use-after-free resulting in a double free in the preinit function at…
- CVE-2022-323531 PoCProduct Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/manage_field_order.php?id=.
- CVE-2022-323911 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-323921 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-323931 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-323941 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-323951 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-323961 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-323971 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-323981 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-323991 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-324001 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-324011 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-324021 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-324031 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-324041 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-324051 PoCPrison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at…
- CVE-2022-324071 PoCSoftr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the Create A New…
- CVE-2022-324092 PoCsA local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows…
- CVE-2022-324142 PoCsNginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vmcode.c.
- CVE-2022-324171 PoCPbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.
- CVE-2022-324294 PoCsAn authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch…
- CVE-2022-324302 PoCsAn access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the…
- CVE-2022-324341 PoCEIPStackGroup OpENer v2.3.0 was discovered to contain a stack overflow via /bin/posix/src/ports/POSIX/OpENer+0x56073d.
- CVE-2022-324411 PoCA memory corruption in Hex Rays Ida Pro v6.6 allows attackers to cause a Denial of Service (DoS) via a crafted file. Related to Data from…
- CVE-2022-324441 PoCAn issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to…
- CVE-2022-324503 PoCsAnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder…
- CVE-2022-324541 PoCA stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of Abode Systems, Inc. iota All-In-One Security Kit…
- CVE-2022-325324 PoCsAuthentication Bypass Vulnerability
- CVE-2022-325431 PoCAn integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a…
- CVE-2022-325482 PoCsAn issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a…
- CVE-2022-325631 PoCAn issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate…
- CVE-2022-325671 PoCThe Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add Auto Indexing…
- CVE-2022-325721 PoCAn os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A…
- CVE-2022-325731 PoCA directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A…
- CVE-2022-325741 PoCA double-free vulnerability exists in the web interface /action/ipcamSetParamPost functionality of Abode Systems, Inc. iota All-In-One…
- CVE-2022-325851 PoCA command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can…
- CVE-2022-325861 PoCAn OS command injection vulnerability exists in the web interface /action/ipcamRecordPost functionality of Abode Systems, Inc. iota…
- CVE-2022-325881 PoCAn out-of-bounds write vulnerability exists in the PICT parsing pctwread_14841 functionality of Accusoft ImageGear 20.0. A…
- CVE-2022-327601 PoCA denial of service vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and…
- CVE-2022-327611 PoCAn information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit…
- CVE-2022-327631 PoCA cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0.…
- CVE-2022-327651 PoCAn OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A…
- CVE-2022-327701 PoCA cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A…
- CVE-2022-327711 PoCA cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A…
- CVE-2022-327721 PoCA cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A…
- CVE-2022-327731 PoCAn OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X…
- CVE-2022-327741 PoCA use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely…
- CVE-2022-327751 PoCAn integer overflow vulnerability exists in the web interface /action/ipcamRecordPost functionality of Abode Systems, Inc. iota All-In-One…
- CVE-2022-328322 PoCsThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7,…
- CVE-2022-328453 PoCsThis issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app…
- CVE-2022-328621 PoCThis issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.7.1, macOS Ventura 13, macOS Monterey…
- CVE-2022-328831 PoCA logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16,…
- CVE-2022-328981 PoCThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13, watchOS…
- CVE-2022-328993 PoCsThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13, watchOS…
- CVE-2022-329321 PoCThe issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16,…
- CVE-2022-329472 PoCsThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An…
- CVE-2022-329483 PoCsAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5.…
- CVE-2022-329781 PoCThere is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS…
- CVE-2022-329811 PoCAn issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and…
- CVE-2022-329851 PoClibnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.
- CVE-2022-329882 PoCsCross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_lwlist,…
- CVE-2022-329931 PoCTOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
- CVE-2022-329941 PoCHalo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.
- CVE-2022-329951 PoCHalo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.
- CVE-2022-329991 PoCThe cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability…