CVE-2022-36000 to CVE-2022-36999
185 CVEs with public proof-of-concept exploits.
- CVE-2022-360071 PoCPartial Path Traversal in com.github.jlangch:venice
- CVE-2022-360561 PoCVulnerabilities with blob verification in sigstore cosign
- CVE-2022-360674 PoCsvm2 vulnerable to Sandbox Escape before v3.9.11
- CVE-2022-360871 PoCOAuthLib vulnerable DoS when attacker provides malicious IPV6 URI
- CVE-2022-360991 PoCXWiki Platform Wiki UI Main Wiki Eval Injection vulnerability
- CVE-2022-361111 PoCimmundb has insufficient verification of data authenticity
- CVE-2022-361232 PoCsThe Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to…
- CVE-2022-361261 PoCAn issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote…
- CVE-2022-361311 PoCThe Better PDF Exporter add-on 10.0.0 for Atlassian Jira is prone to stored XSS via a crafted description to the PDF Templates overview…
- CVE-2022-361361 PoCChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input Deposit Comment.
- CVE-2022-361371 PoCChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input sHeader.
- CVE-2022-361391 PoCSWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via SWF::Writer::writeByte(unsigned char).
- CVE-2022-361401 PoCSWFMill commit 53d7690 was discovered to contain a segmentation violation via SWF::DeclareFunction2::write(SWF::Writer*, SWF::Context*).
- CVE-2022-361411 PoCSWFMill commit 53d7690 was discovered to contain a segmentation violation via SWF::MethodBody::write(SWF::Writer*, SWF::Context*).
- CVE-2022-361421 PoCSWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via SWF::Reader::getU30().
- CVE-2022-361431 PoCSWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via __interceptor_strlen.part at…
- CVE-2022-361441 PoCSWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via base64_encode.
- CVE-2022-361451 PoCSWFMill commit 53d7690 was discovered to contain a segmentation violation via SWF::Reader::getWord().
- CVE-2022-361461 PoCSWFMill commit 53d7690 was discovered to contain a memory allocation issue via operator new[](unsigned long) at asan_new_delete.cpp.
- CVE-2022-361481 PoCfdkaac commit 53fe239 was discovered to contain a floating point exception (FPE) via wav_open at /src/wav_reader.c.
- CVE-2022-361611 PoCOrange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
- CVE-2022-361701 PoCMapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion.
- CVE-2022-361711 PoCMapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.
- CVE-2022-361731 PoCFreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the FreshAgent client and…
- CVE-2022-361741 PoCFreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken…
- CVE-2022-361791 PoCFusiondirectory 1.3 suffers from Improper Session Handling.
- CVE-2022-361801 PoCFusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection],…
- CVE-2022-361861 PoCA Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at…
- CVE-2022-361901 PoCGPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed…
- CVE-2022-361911 PoCA heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by MP4Box. This…
- CVE-2022-361932 PoCsSQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the…
- CVE-2022-361942 PoCsCentreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload…
- CVE-2022-361971 PoCBigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a…
- CVE-2022-361981 PoCMultiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php,…
- CVE-2022-362001 PoCIn FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.
- CVE-2022-362011 PoCDoctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.
- CVE-2022-362031 PoCDoctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the…
- CVE-2022-362151 PoCDedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php.
- CVE-2022-362161 PoCDedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.
- CVE-2022-362241 PoCXunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).
- CVE-2022-362251 PoCEyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
- CVE-2022-362261 PoCSiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.
- CVE-2022-362311 PoCpdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
- CVE-2022-362342 PoCsSimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnerability which is…
- CVE-2022-362511 PoCClinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php.
- CVE-2022-362551 PoCA SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL…
- CVE-2022-362561 PoCA SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands…
- CVE-2022-362571 PoCA SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands…
- CVE-2022-362581 PoCA SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL…
- CVE-2022-362621 PoCAn issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
- CVE-2022-362673 PoCsIn Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping…
- CVE-2022-362711 PoCOutbyte PC Repair Installation File 1.7.112.7856 is vulnerable to Dll Hijacking. iertutil.dll is missing so an attacker can use a…
- CVE-2022-362731 PoCTenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.
- CVE-2022-362791 PoCA stack-based buffer overflow vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A…
- CVE-2022-363061 PoCAn authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web…
- CVE-2022-363091 PoCAirspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter…
- CVE-2022-363101 PoCAirspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an…
- CVE-2022-363541 PoCA heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More…
- CVE-2022-364291 PoCA command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5. A…
- CVE-2022-364321 PoCThe Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform…
- CVE-2022-364331 PoCThe blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the…
- CVE-2022-364361 PoCOSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass…
- CVE-2022-364401 PoCA reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct…
- CVE-2022-364469 PoCssoftware/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
- CVE-2022-364551 PoCTOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability via the username parameter in…
- CVE-2022-364561 PoCTOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in…
- CVE-2022-364581 PoCTOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the…
- CVE-2022-364591 PoCTOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the host_time parameter in the…
- CVE-2022-364601 PoCTOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the…
- CVE-2022-364611 PoCTOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the…
- CVE-2022-364621 PoCTOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.
- CVE-2022-364631 PoCTOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command parameter in the function…
- CVE-2022-364641 PoCTOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the sPort parameter in the function…
- CVE-2022-364651 PoCTOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser parameter.
- CVE-2022-364661 PoCTOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
- CVE-2022-364671 PoCH3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function EditMacList.d.
- CVE-2022-364681 PoCH3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function Asp_SetTimingtimeWifiAndLed.
- CVE-2022-364691 PoCH3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById.
- CVE-2022-364701 PoCH3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetAP5GWifiById.
- CVE-2022-364711 PoCH3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetMacAccessMode.
- CVE-2022-364721 PoCH3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function SetMobileAPInfoById.
- CVE-2022-364731 PoCH3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G.
- CVE-2022-364741 PoCH3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function WlanWpsSet.
- CVE-2022-364751 PoCH3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function AddMacList.
- CVE-2022-364771 PoCH3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function AddWlanMacList.
- CVE-2022-364781 PoCH3C B5 Mini B5MiniV100R005 was discovered to contain a stack overflow via the function Edit_BasicSSID.
- CVE-2022-364791 PoCTOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the host_time parameter in the…
- CVE-2022-364801 PoCTOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the command parameter in the function…
- CVE-2022-364811 PoCTOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function…
- CVE-2022-364821 PoCTOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the lang parameter in the function…
- CVE-2022-364831 PoCTOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the pppoeUser parameter.
- CVE-2022-364841 PoCTOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the function setDiagnosisCfg.
- CVE-2022-364851 PoCTOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the…
- CVE-2022-364861 PoCTOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the…
- CVE-2022-364871 PoCTOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the…
- CVE-2022-364881 PoCTOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the sPort parameter in the function…
- CVE-2022-364891 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function EnableIpv6.
- CVE-2022-364901 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function EditMacList.
- CVE-2022-364911 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function UpdateIpv6Params.
- CVE-2022-364921 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function AddMacList.
- CVE-2022-364931 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById.
- CVE-2022-364941 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function edditactionlist.
- CVE-2022-364951 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function addactionlist.
- CVE-2022-364961 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function SetMobileAPInfoById.
- CVE-2022-364971 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G.
- CVE-2022-364981 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function Asp_SetTimingtimeWifiAndLed.
- CVE-2022-364991 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function DEleteusergroup.
- CVE-2022-365001 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function EditWlanMacList.
- CVE-2022-365011 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function UpdateSnat.
- CVE-2022-365021 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function UpdateWanParams.
- CVE-2022-365031 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function UpdateMacClone.
- CVE-2022-365041 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function Edit_BasicSSID.
- CVE-2022-365051 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function EDitusergroup.
- CVE-2022-365061 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function SetMacAccessMode.
- CVE-2022-365071 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function AddWlanMacList.
- CVE-2022-365081 PoCH3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function SetAPInfoById.
- CVE-2022-365091 PoCH3C GR3200 MiniGR1B0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
- CVE-2022-365101 PoCH3C GR2200 MiniGR1A0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
- CVE-2022-365111 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function EditApAdvanceInfo.
- CVE-2022-365131 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function edditactionlist.
- CVE-2022-365141 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function WanModeSetMultiWan.
- CVE-2022-365151 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function addactionlist.
- CVE-2022-365161 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function ap_version_check.
- CVE-2022-365171 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function debug_wlan_advance.
- CVE-2022-365181 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function EditWlanMacList.
- CVE-2022-365191 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function AddWlanMacList.
- CVE-2022-365201 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function DEleteusergroup.
- CVE-2022-365221 PoCMikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component…
- CVE-2022-365322 PoCsBolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload…
- CVE-2022-365342 PoCsSuper Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution…
- CVE-2022-365361 PoCAn issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows…
- CVE-2022-365375 PoCsKEVZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request…
- CVE-2022-365391 PoCWeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other…
- CVE-2022-365431 PoCEdoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.
- CVE-2022-365441 PoCEdoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.
- CVE-2022-365451 PoCEdoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.
- CVE-2022-365461 PoCEdoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php.
- CVE-2022-365511 PoCA Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier…
- CVE-2022-365532 PoCsHytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component…
- CVE-2022-365611 PoCXPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.
- CVE-2022-365681 PoCTenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the list parameter at /goform/setPptpUserList.
- CVE-2022-365691 PoCTenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg.
- CVE-2022-365701 PoCTenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.
- CVE-2022-365711 PoCTenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting.
- CVE-2022-365721 PoCSinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component…
- CVE-2022-365771 PoCAn issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
- CVE-2022-365791 PoCWellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).
- CVE-2022-365801 PoCAn arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows…
- CVE-2022-365811 PoCOnline Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.
- CVE-2022-365821 PoCAn arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to…
- CVE-2022-365931 PoCkkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at…
- CVE-2022-366061 PoCYwoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.
- CVE-2022-366191 PoCIn D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.
- CVE-2022-366201 PoCD-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.
- CVE-2022-366333 PoCsTeleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent…
- CVE-2022-366341 PoCAn access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.
- CVE-2022-366351 PoCZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.
- CVE-2022-366361 PoCGarage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.
- CVE-2022-366371 PoCGarage Management System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the brand_name parameter…
- CVE-2022-366381 PoCAn access control issue in the component print.php of Garage Management System v1.0 allows unauthenticated attackers to access data for…
- CVE-2022-366391 PoCA stored cross-site scripting (XSS) vulnerability in /client.php of Garage Management System v1.0 allows attackers to execute arbitrary…
- CVE-2022-366423 PoCsA local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to…
- CVE-2022-366471 PoCPKUVCL davs2 v1.6.205 was discovered to contain a global buffer overflow via the function parse_sequence_header() at…
- CVE-2022-366571 PoCLibrary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component…
- CVE-2022-366631 PoCGluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
- CVE-2022-366643 PoCsPassword Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.
- CVE-2022-366671 PoCGarage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function.…
- CVE-2022-366681 PoCGarage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabilities exist during…
- CVE-2022-366692 PoCsHospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
- CVE-2022-366701 PoCPCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator…
- CVE-2022-367491 PoCRPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This…
- CVE-2022-367521 PoCpng2webp v1.0.4 was discovered to contain an out-of-bounds write via the function w2p. This vulnerability is exploitable via a crafted png…
- CVE-2022-367561 PoCDIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
- CVE-2022-367793 PoCsPROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection
- CVE-2022-367801 PoCAvdor CIS - crystal quality Credentials Management Errors
- CVE-2022-367881 PoCA heap-based buffer overflow vulnerability exists in the TriangleMesh clone functionality of Slic3r libslic3r 1.3.0 and Master Commit…
- CVE-2022-3680425 PoCsKEVMultiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version…
- CVE-2022-368801 PoCThe Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.
- CVE-2022-368832 PoCsA missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured…
- CVE-2022-369231 PoCZoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and…
- CVE-2022-369342 PoCsAn integer overflow in WhatsApp could result in remote code execution in an established video call.
- CVE-2022-369431 PoCSSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths which are…
- CVE-2022-369441 PoCScala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in…
- CVE-2022-369453 PoCsThe Remote Keyless Entry (RKE) receiving unit on certain Mazda vehicles through 2020 allows remote attackers to perform unlock operations…
- CVE-2022-369462 PoCsnfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service…