CVE-2022-34000 to CVE-2022-34999
113 CVEs with public proof-of-concept exploits.
- CVE-2022-340001 PoClibjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc.
- CVE-2022-340011 PoCUnit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.
- CVE-2022-340021 PoCThe ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusion vulnerability…
- CVE-2022-340071 PoCEQS Integrity Line Professional through 2022-07-01 allows a stored XSS via a crafted whistleblower entry.
- CVE-2022-340081 PoCComodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can…
- CVE-2022-340201 PoCCross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows…
- CVE-2022-340211 PoCMultiple Cross Site Scripting (XSS) vulnerabilities in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via the form fields.
- CVE-2022-340221 PoCSQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST request to…
- CVE-2022-340271 PoCNginx NJS v0.7.4 was discovered to contain a segmentation violation via njs_value_property at njs_value.c.
- CVE-2022-340281 PoCNginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h.
- CVE-2022-340291 PoCNginx NJS v0.7.4 was discovered to contain an out-of-bounds read via njs_scope_value at njs_scope.h.
- CVE-2022-340301 PoCNginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_djb_hash at src/njs_djb_hash.c.
- CVE-2022-340311 PoCNginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_value_to_number at src/njs_value_conversion.h.
- CVE-2022-340321 PoCNginx NJS v0.7.5 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.
- CVE-2022-340331 PoCHTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273.
- CVE-2022-340351 PoCHTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588.
- CVE-2022-340451 PoCWavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at…
- CVE-2022-340462 PoCsAn access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via…
- CVE-2022-340473 PoCsAn access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via…
- CVE-2022-340482 PoCsWavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page…
- CVE-2022-340491 PoCAn access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration…
- CVE-2022-340671 PoCWarehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.
- CVE-2022-340923 PoCsPortal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via svg2img.php.
- CVE-2022-340934 PoCsPortal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via…
- CVE-2022-340944 PoCsPortal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via…
- CVE-2022-341131 PoCAn issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
- CVE-2022-341213 PoCsCuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component…
- CVE-2022-341251 PoCfront/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/…
- CVE-2022-341271 PoCThe Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.
- CVE-2022-341281 PoCThe Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
- CVE-2022-341404 PoCsA stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary…
- CVE-2022-341551 PoCWordPress OAuth Single Sign On – SSO (OAuth Client) Plugin <= 6.23.3 is vulnerable to Broken Authentication
- CVE-2022-341693 PoCsApache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
- CVE-2022-342655 PoCsAn issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL…
- CVE-2022-342672 PoCsAn issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication…
- CVE-2022-342681 PoCAn issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to…
- CVE-2022-342691 PoCAn issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id=…
- CVE-2022-342701 PoCAn issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.
- CVE-2022-342961 PoCIn Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.
- CVE-2022-342981 PoCThe NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
- CVE-2022-342991 PoCThere is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
- CVE-2022-343001 PoCIn tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
- CVE-2022-343052 PoCsXSS in examples web application
- CVE-2022-343282 PoCsPMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.
- CVE-2022-344871 PoCWordPress Shortcode Addons plugin <= 3.0.2 - Unauthenticated Arbitrary Option Update vulnerability
- CVE-2022-344961 PoCHiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.
- CVE-2022-345021 PoCRadare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm/wasm.c. This…
- CVE-2022-345201 PoCRadare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_load_buffer at bin/bfile.c. This…
- CVE-2022-345262 PoCsA stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial…
- CVE-2022-345271 PoCD-Link DSL-3782 v1.03 and below was discovered to contain a command injection vulnerability via the function byte_4C0160.
- CVE-2022-345291 PoCWASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill.
- CVE-2022-345341 PoCDigital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.
- CVE-2022-345491 PoCSims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows…
- CVE-2022-345501 PoCSims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This vulnerability…
- CVE-2022-345511 PoCSims v1.0 was discovered to allow path traversal when downloading attachments.
- CVE-2022-345561 PoCPicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c.
- CVE-2022-345671 PoCAn issue in \Roaming\Mango\Plugins of University of Texas Multi-image Analysis GUI (Mango) 4.1 allows attackers to escalate privileges via…
- CVE-2022-345701 PoCWAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information…
- CVE-2022-345711 PoCAn access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the system key information and…
- CVE-2022-345721 PoCAn access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet password via…
- CVE-2022-345731 PoCAn access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configure device settings…
- CVE-2022-345741 PoCAn access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the…
- CVE-2022-345751 PoCAn access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the…
- CVE-2022-345762 PoCsA vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a…
- CVE-2022-345771 PoCA vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
- CVE-2022-345781 PoCOpen Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
- CVE-2022-345901 PoCHospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.
- CVE-2022-345931 PoCDPTech VPN v8.1.28.0 was discovered to contain an arbitrary file read vulnerability.
- CVE-2022-345991 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm.
- CVE-2022-346001 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm.
- CVE-2022-346011 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm.
- CVE-2022-346021 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.
- CVE-2022-346031 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm.
- CVE-2022-346041 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /dotrace.asp.
- CVE-2022-346051 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /dotrace.asp.
- CVE-2022-346061 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditvsList parameter at /dotrace.asp.
- CVE-2022-346071 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /doping.asp.
- CVE-2022-346081 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ajaxmsg parameter at /AJAX/ajaxget.
- CVE-2022-346091 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /doping.asp.
- CVE-2022-346101 PoCH3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the URL /ihomers/app.
- CVE-2022-346181 PoCA stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2022-346191 PoCA stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2022-346621 PoCApache DolphinScheduler prior to 3.0.0 allows path traversal
- CVE-2022-346681 PoCNVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an…
- CVE-2022-346831 PoCNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a…
- CVE-2022-347151 PoCWindows Network File System Remote Code Execution Vulnerability
- CVE-2022-347183 PoCsWindows TCP/IP Remote Code Execution Vulnerability
- CVE-2022-347533 PoCsA CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause…
- CVE-2022-348451 PoCA firmware update vulnerability exists in the sysupgrade functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network…
- CVE-2022-348501 PoCAn OS command injection vulnerability exists in the web_server /action/import_authorized_keys/ functionality of Robustel R1510 3.1.16 and…
- CVE-2022-348941 PoCIn JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
- CVE-2022-349032 PoCsGnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other…
- CVE-2022-349061 PoCA hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated…
- CVE-2022-349071 PoCAn authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an…
- CVE-2022-349131 PoCmd2roff 1.7 has a stack-based buffer overflow via a Markdown file containing a large number of consecutive characters to be processed.…
- CVE-2022-3491811 PoCsAn issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could…
- CVE-2022-349191 PoCThe file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading…
- CVE-2022-349241 PoCLanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the…
- CVE-2022-349371 PoCYuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows…
- CVE-2022-349551 PoCPligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at…
- CVE-2022-349561 PoCPligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php.
- CVE-2022-349601 PoCThe container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to…
- CVE-2022-349612 PoCsOpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via…
- CVE-2022-349622 PoCsOpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via…
- CVE-2022-349632 PoCsOpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via…
- CVE-2022-349641 PoCOpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via…
- CVE-2022-349651 PoCOpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component…
- CVE-2022-349661 PoCOpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location…
- CVE-2022-349681 PoCAn issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL…
- CVE-2022-349701 PoCCrow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this…
- CVE-2022-349721 PoCSo Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id ,…
- CVE-2022-349881 PoCInout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/js.
- CVE-2022-349891 PoCFruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php.