CVE-2022-37000 to CVE-2022-37999
155 CVEs with public proof-of-concept exploits.
- CVE-2022-370171 PoCSymantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass…
- CVE-2022-370301 PoCWeak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a local unprivileged…
- CVE-2022-370321 PoCAn out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in…
- CVE-2022-370352 PoCsAn issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is…
- CVE-2022-370428 PoCsKEVZimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By…
- CVE-2022-370471 PoCThe component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713.…
- CVE-2022-370481 PoCThe component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at…
- CVE-2022-370491 PoCThe component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE:…
- CVE-2022-370501 PoCIn Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by…
- CVE-2022-370511 PoCAn issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in…
- CVE-2022-370521 PoCA reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.
- CVE-2022-370561 PoCD-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,
- CVE-2022-370571 PoCD-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.
- CVE-2022-370591 PoCCross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field
- CVE-2022-370601 PoCFLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access…
- CVE-2022-370618 PoCsAll FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited…
- CVE-2022-370661 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateDDNS.
- CVE-2022-370671 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanParamsMulti.
- CVE-2022-370681 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateMacCloneFinal.
- CVE-2022-370691 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateSnat.
- CVE-2022-370701 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
- CVE-2022-370711 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateOne2One.
- CVE-2022-370721 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanLinkspyMulti.
- CVE-2022-370731 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanModeMulti.
- CVE-2022-370741 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function switch_debug_info_set.
- CVE-2022-370751 PoCTOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
- CVE-2022-370761 PoCTOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the…
- CVE-2022-370771 PoCTOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the pppoeUser parameter.
- CVE-2022-370781 PoCTOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the lang parameter at…
- CVE-2022-370791 PoCTOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the hostName parameter in the…
- CVE-2022-370801 PoCTOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the command parameter at setting/setTracerouteCfg.
- CVE-2022-370811 PoCTOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the command parameter at…
- CVE-2022-370821 PoCTOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the host_time parameter at the…
- CVE-2022-370831 PoCTOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the ip parameter at the function…
- CVE-2022-370841 PoCTOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the sPort parameter at the addEffect function.
- CVE-2022-370851 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the AddWlanMacList function.
- CVE-2022-370861 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function Asp_SetTimingtimeWifiAndLed.
- CVE-2022-370871 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetMobileAPInfoById.
- CVE-2022-370881 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAP5GWifiById.
- CVE-2022-370891 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditMacList.
- CVE-2022-370901 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID.
- CVE-2022-370911 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditWlanMacList.
- CVE-2022-370921 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById.
- CVE-2022-370931 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function AddMacList.
- CVE-2022-370941 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID_5G.
- CVE-2022-370951 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateWanParams.
- CVE-2022-370961 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6.
- CVE-2022-370971 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPInfoById.
- CVE-2022-370981 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateIpv6Params.
- CVE-2022-370991 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateSnat.
- CVE-2022-371001 PoCH3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateMacClone.
- CVE-2022-371092 PoCspatrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access…
- CVE-2022-371224 PoCsCarel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an…
- CVE-2022-371231 PoCD-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
- CVE-2022-371251 PoCD-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
- CVE-2022-371281 PoCIn D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
- CVE-2022-371291 PoCD-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command…
- CVE-2022-371301 PoCIn D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the…
- CVE-2022-371331 PoCD-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot…
- CVE-2022-371341 PoCD-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be…
- CVE-2022-371371 PoCPayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under…
- CVE-2022-371381 PoCLoan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator…
- CVE-2022-371391 PoCLoan Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
- CVE-2022-371401 PoCPayMoney 3.3 is vulnerable to Client Side Remote Code Execution (RCE). The vulnerability exists on the reply ticket function and upload…
- CVE-2022-371531 PoCAn issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
- CVE-2022-371552 PoCsRCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.
- CVE-2022-371591 PoCClaroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
- CVE-2022-371601 PoCClaroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By…
- CVE-2022-371611 PoCClaroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
- CVE-2022-371621 PoCClaroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding…
- CVE-2022-371771 PoCHireVue Hiring Platform V1.0 suffers from Use of a Broken or Risky Cryptographic Algorithm. NOTE: this is disputed by the vendor for…
- CVE-2022-371831 PoCPiwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list.
- CVE-2022-371841 PoCThe application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authenticated malicious…
- CVE-2022-371901 PoCCuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from…
- CVE-2022-371913 PoCsThe component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST…
- CVE-2022-371971 PoCIOBit IOTransfer V4 is vulnerable to Unquoted Service Path.
- CVE-2022-372012 PoCsJFinal CMS 5.1.0 is vulnerable to SQL Injection.
- CVE-2022-372022 PoCsJFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list
- CVE-2022-372032 PoCsJFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses…
- CVE-2022-372042 PoCsFinal CMS 5.1.0 is vulnerable to SQL Injection.
- CVE-2022-372052 PoCsJFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses…
- CVE-2022-372072 PoCsJFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses…
- CVE-2022-372082 PoCsJFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses…
- CVE-2022-372092 PoCsJFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses…
- CVE-2022-372552 PoCsTP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603.
- CVE-2022-372921 PoCTenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, which satisfies the…
- CVE-2022-372991 PoCAn issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file read via…
- CVE-2022-373053 PoCsThe Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform unlock operations…
- CVE-2022-373061 PoCOX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.
- CVE-2022-373071 PoCOX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an…
- CVE-2022-373081 PoCOX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
- CVE-2022-373091 PoCOX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
- CVE-2022-373101 PoCOX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a…
- CVE-2022-373111 PoCOX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.
- CVE-2022-373121 PoCOX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer…
- CVE-2022-373131 PoCOX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
- CVE-2022-373311 PoCAn out-of-bounds write vulnerability exists in the Gaussian format orientation functionality of Open Babel 3.1.1 and master commit…
- CVE-2022-373322 PoCsA use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted…
- CVE-2022-373371 PoCA command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted…
- CVE-2022-373933 PoCsZimbra zmslapd arbitrary module load
- CVE-2022-374151 PoCThe Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL 0x40002008.
- CVE-2022-374161 PoCIttiam libmpeg2 before 2022-07-27 uses memcpy with overlapping memory blocks in impeg2_mc_fullx_fully_8x8.
- CVE-2022-374183 PoCsThe Remote Keyless Entry (RKE) receiving unit on certain Nissan, Kia, and Hyundai vehicles through 2017 allows remote attackers to perform…
- CVE-2022-374221 PoCPayara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server…
- CVE-2022-374343 PoCszlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.…
- CVE-2022-374541 PoCThe Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers…
- CVE-2022-374611 PoCMultiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject…
- CVE-2022-374621 PoCA stored Cross-Site Scripting (XSS) vulnerability in the Chat gadget in Upstream Works Agent Desktop for Cisco Finesse through 4.2.12 and…
- CVE-2022-376012 PoCsPrototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js.…
- CVE-2022-376613 PoCsSmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
- CVE-2022-377041 PoCAmanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute…
- CVE-2022-377051 PoCA privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerable component is…
- CVE-2022-3770611 PoCsenlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library…
- CVE-2022-377091 PoCTesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing. Tesla Model 3's…
- CVE-2022-377181 PoCThe management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This…
- CVE-2022-377191 PoCA Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and…
- CVE-2022-377311 PoCftcms 2.1 poster.PHP has a XSS vulnerability. The attacker inserts malicious JavaScript code into the web page, causing the user /…
- CVE-2022-377681 PoClibjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.
- CVE-2022-377691 PoClibjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability…
- CVE-2022-377701 PoClibjpeg commit 281daa9 was discovered to contain a segmentation fault via LineMerger::GetNextLowpassLine at linemerger.cpp. This…
- CVE-2022-377712 PoCsIObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges…
- CVE-2022-377751 PoCGenesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History…
- CVE-2022-377811 PoCfdkaac v1.0.3 was discovered to contain a heap buffer overflow via __interceptor_memcpy.part.46 at…
- CVE-2022-377941 PoCIn Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.
- CVE-2022-377971 PoCIn lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is…
- CVE-2022-377981 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.
- CVE-2022-377991 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.
- CVE-2022-378001 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.
- CVE-2022-378011 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
- CVE-2022-378021 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting.
- CVE-2022-378031 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat.
- CVE-2022-378041 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo.
- CVE-2022-378051 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle.
- CVE-2022-378061 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient.
- CVE-2022-378071 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState.
- CVE-2022-378081 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.
- CVE-2022-378091 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.
- CVE-2022-378101 PoCTenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
- CVE-2022-378111 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer.
- CVE-2022-378121 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg.
- CVE-2022-378131 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.
- CVE-2022-378141 PoCTenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the…
- CVE-2022-378151 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex.
- CVE-2022-378161 PoCTenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.
- CVE-2022-378171 PoCTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetIpMacBind.
- CVE-2022-378181 PoCTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
- CVE-2022-378191 PoCTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the timezone parameter in the function fromSetSysTime.
- CVE-2022-378201 PoCTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the function formSetSysToolDDNS.
- CVE-2022-378211 PoCTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ProvinceCode parameter in the function formSetProvince.
- CVE-2022-378221 PoCTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetRouteStatic.
- CVE-2022-378231 PoCTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetVirtualSer.
- CVE-2022-378241 PoCTenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic.
- CVE-2022-379322 PoCsA potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches.…
- CVE-2022-379695 PoCsKEVWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-379711 PoCMicrosoft Windows Defender Elevation of Privilege Vulnerability