CVE-2022-33000 to CVE-2022-33999
57 CVEs with public proof-of-concept exploits.
- CVE-2022-330111 PoCKnown v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection attack.
- CVE-2022-330121 PoCMicroweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
- CVE-2022-330241 PoCThere is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *'…
- CVE-2022-330251 PoCLibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c.
- CVE-2022-330261 PoCLibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
- CVE-2022-330271 PoCLibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c.
- CVE-2022-330281 PoCLibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c.
- CVE-2022-330321 PoCLibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.
- CVE-2022-330331 PoCLibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.
- CVE-2022-330341 PoCLibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.
- CVE-2022-330431 PoCA cross-site scripting (XSS) vulnerability in the batch add function of Urtracker Premium v4.0.1.1477 allows attackers to execute…
- CVE-2022-330752 PoCsA stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to…
- CVE-2022-330821 PoCAn issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted…
- CVE-2022-330871 PoCA stack overflow in the function DM_ In fillobjbystr() of TP-Link Archer C50&A5(US)_V5_200407 allows attackers to cause a Denial of…
- CVE-2022-330984 PoCsMagnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This…
- CVE-2022-330991 PoCAn issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
- CVE-2022-331072 PoCsThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component…
- CVE-2022-331083 PoCsXPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.
- CVE-2022-331161 PoCAn issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows…
- CVE-2022-331192 PoCsNUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.
- CVE-2022-331211 PoCA Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious…
- CVE-2022-331221 PoCA stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2022-331241 PoCAIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: multiple third…
- CVE-2022-331401 PoCImproper Neutralization of Command Elements in Shell User Group Provider
- CVE-2022-331501 PoCAn OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A specially-crafted network…
- CVE-2022-331712 PoCsThe findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function…
- CVE-2022-331743 PoCsPower Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web…
- CVE-2022-331751 PoCPower Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the…
- CVE-2022-331891 PoCAn OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z.…
- CVE-2022-331921 PoCFour OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit…
- CVE-2022-331931 PoCFour OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit…
- CVE-2022-331941 PoCFour OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit…
- CVE-2022-331951 PoCFour OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit…
- CVE-2022-331981 PoCWordPress Accordions plugin <= 2.0.2 - Unauthenticated WordPress Options Change vulnerability
- CVE-2022-332041 PoCFour OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota…
- CVE-2022-332051 PoCFour OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota…
- CVE-2022-332061 PoCFour OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota…
- CVE-2022-332071 PoCFour OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota…
- CVE-2022-333121 PoCMultiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A…
- CVE-2022-333131 PoCMultiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A…
- CVE-2022-333141 PoCMultiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0. A…
- CVE-2022-333181 PoCDeserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64…
- CVE-2022-333251 PoCMultiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A…
- CVE-2022-333261 PoCMultiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A…
- CVE-2022-333271 PoCMultiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A…
- CVE-2022-333281 PoCMultiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A…
- CVE-2022-333291 PoCMultiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A…
- CVE-2022-3367910 PoCsWindows Kerberos Elevation of Privilege Vulnerability
- CVE-2022-3389114 PoCsKEVApache Spark shell command injection vulnerability via Spark UI
- CVE-2022-338961 PoCA buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A…
- CVE-2022-338971 PoCA directory traversal vulnerability exists in the web_server /ajax/remove/ functionality of Robustel R1510 3.1.16. A specially-crafted…
- CVE-2022-339011 PoCWordPress MultiSafepay plugin for WooCommerce plugin <= 4.13.1 - Unauthenticated Arbitrary File Read vulnerability
- CVE-2022-339102 PoCsAn XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When…
- CVE-2022-339381 PoCA format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One…
- CVE-2022-339651 PoCWordPress WP Visitor Statistics plugin <= 5.7 - Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities
- CVE-2022-339806 PoCsApache Commons Configuration insecure interpolation defaults
- CVE-2022-339811 PoCdrivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency use-after-free…