CVE-2022-38000 to CVE-2022-38999
129 CVEs with public proof-of-concept exploits.
- CVE-2022-380231 PoCNetlogon RPC Elevation of Privilege Vulnerability
- CVE-2022-380291 PoCWindows ALPC Elevation of Privilege Vulnerability
- CVE-2022-380651 PoCA privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly…
- CVE-2022-380661 PoCAn OS command injection vulnerability exists in the httpd SNMP functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A…
- CVE-2022-380721 PoCAn improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and…
- CVE-2022-380881 PoCA directory traversal vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A…
- CVE-2022-381051 PoCAn information disclosure vulnerability exists in the cm_processREQ_NC opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's…
- CVE-2022-381081 PoCSolarWinds Platform Deserialization of Untrusted Data
- CVE-2022-381301 PoCThe com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It…
- CVE-2022-381311 PoCRStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to…
- CVE-2022-381431 PoCA heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp…
- CVE-2022-381521 PoCAn issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its…
- CVE-2022-381531 PoCAn issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable.…
- CVE-2022-381681 PoCBroken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated…
- CVE-2022-381817 PoCsKEVThe Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects…
- CVE-2022-382221 PoCThere is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted…
- CVE-2022-382231 PoCThere is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m…
- CVE-2022-382721 PoCJFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.
- CVE-2022-382731 PoCJFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.
- CVE-2022-382741 PoCJFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.
- CVE-2022-382751 PoCJFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.
- CVE-2022-382761 PoCJFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.
- CVE-2022-382771 PoCJFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.
- CVE-2022-382781 PoCJFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.
- CVE-2022-382791 PoCJFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list.
- CVE-2022-382801 PoCJFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.
- CVE-2022-382811 PoCJFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.
- CVE-2022-382952 PoCsCuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability…
- CVE-2022-382962 PoCsCuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
- CVE-2022-383051 PoCAeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability…
- CVE-2022-383061 PoCLIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.
- CVE-2022-383071 PoCLIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at…
- CVE-2022-383081 PoCTOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function…
- CVE-2022-383091 PoCTenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at…
- CVE-2022-383101 PoCTenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at…
- CVE-2022-383111 PoCTenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.
- CVE-2022-383121 PoCTenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.
- CVE-2022-383131 PoCTenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at…
- CVE-2022-383141 PoCTenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at…
- CVE-2022-383251 PoCTenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the…
- CVE-2022-383261 PoCTenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the…
- CVE-2022-383291 PoCA CSRF vulnerability in Shopxian CMS 3.0.0 could allow an unauthenticated, remote attacker to craft a malicious link, potentially causing…
- CVE-2022-383341 PoCXPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.
- CVE-2022-383351 PoCVtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
- CVE-2022-383491 PoCAn issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because…
- CVE-2022-383511 PoCA vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted…
- CVE-2022-383571 PoCImproper neutralization of special elements leaves the Eyes of Network Web application vulnerable to an iFrame injection attack, via the…
- CVE-2022-383581 PoCImproper neutralization of input during web page generation leaves the Eyes of Network web application vulnerable to cross-site scripting…
- CVE-2022-383591 PoCCross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate…
- CVE-2022-383742 PoCsA improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 - 7.0.2 and 6.2.0 -…
- CVE-2022-383931 PoCA denial of service vulnerability exists in the cfg_server cm_processConnDiagPktList opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230…
- CVE-2022-384511 PoCA directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request…
- CVE-2022-384521 PoCA command execution vulnerability exists in the hidden telnet service functionality of Netgear Orbi Router RBR750 4.6.8.5. A…
- CVE-2022-384581 PoCA cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5. A…
- CVE-2022-384591 PoCA stack-based buffer overflow vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020.…
- CVE-2022-384631 PoCServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.
- CVE-2022-384671 PoCWordPress CRM Perks Forms Plugin <= 1.1.0 is vulnerable to Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2022-384881 PoClogrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.
- CVE-2022-384951 PoCLIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.
- CVE-2022-384961 PoCLIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.
- CVE-2022-384971 PoCLIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69.
- CVE-2022-385101 PoCTenda_TX9pro V22.03.02.10 was discovered to contain a buffer overflow via the component httpd/SetNetControlList.
- CVE-2022-385111 PoCTOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downloadFile.cgi.
- CVE-2022-385281 PoCOpen Asset Import Library (assimp) commit 3c253ca was discovered to contain a segmentation violation via the component…
- CVE-2022-385291 PoCtinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress.
- CVE-2022-385301 PoCGPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD.
- CVE-2022-385321 PoCMicro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Features of…
- CVE-2022-385341 PoCTOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg function.
- CVE-2022-385351 PoCTOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg function.
- CVE-2022-385532 PoCsAcademy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the…
- CVE-2022-385551 PoCLinksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
- CVE-2022-385561 PoCTrendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
- CVE-2022-385621 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This…
- CVE-2022-385631 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This…
- CVE-2022-385641 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability…
- CVE-2022-385651 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability…
- CVE-2022-385661 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability…
- CVE-2022-385681 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This…
- CVE-2022-385701 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers…
- CVE-2022-385711 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow in the function formSetGuideListItem.
- CVE-2022-385731 PoC10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.
- CVE-2022-385772 PoCsProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to…
- CVE-2022-385801 PoCZalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
- CVE-2022-385821 PoCIncorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arbitrary files.
- CVE-2022-385991 PoCTeleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web…
- CVE-2022-386041 PoCWacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability.
- CVE-2022-386111 PoCIncorrect access control in Watchdog Anti-Virus v1.4.158 allows attackers to perform a DLL hijacking attack and execute arbitrary code via…
- CVE-2022-386211 PoCDoufox v0.0.4 was discovered to contain a remote code execution (RCE) vulnerability via the edit file page. This vulnerability allows…
- CVE-2022-386272 PoCsNortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL…
- CVE-2022-386281 PoCNortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a…
- CVE-2022-386372 PoCsHospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters…
- CVE-2022-386682 PoCsHTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when…
- CVE-2022-386911 PoCIn BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no…
- CVE-2022-386949 PoCsIn BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution…
- CVE-2022-387151 PoCA leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A…
- CVE-2022-387251 PoCAn integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service…
- CVE-2022-387501 PoCDoS in SnakeYAML
- CVE-2022-387662 PoCsThe remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for each door-open…
- CVE-2022-387891 PoCAn issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and the PSK to…
- CVE-2022-387941 PoCZaver through 2020-12-15 allows directory traversal via the GET /.. substring.
- CVE-2022-387961 PoCA Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by…
- CVE-2022-388081 PoCywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.
- CVE-2022-388121 PoCAeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
- CVE-2022-388132 PoCsPHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access…
- CVE-2022-388141 PoCA stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to…
- CVE-2022-388172 PoCsDapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.
- CVE-2022-388261 PoCIn TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.
- CVE-2022-388271 PoCTOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi
- CVE-2022-388281 PoCTOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi
- CVE-2022-388291 PoCTenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setMacFilterCfg.
- CVE-2022-388301 PoCTenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setIPv6Status.
- CVE-2022-388311 PoCTenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/SetNetControlList
- CVE-2022-388403 PoCscgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to…
- CVE-2022-388412 PoCsLinksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute…
- CVE-2022-388431 PoCEspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the…
- CVE-2022-388441 PoCCSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with…
- CVE-2022-388451 PoCCross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending…
- CVE-2022-388461 PoCEspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel…
- CVE-2022-388671 PoCSQL Injection vulnerability in rttys versions 4.0.0, 4.0.1, 4.0.2, and 4.4.x in api.go, allows attackers to execute arbitrary code.
- CVE-2022-388681 PoCSQL Injection vulnerability in Ehoney version 2.0.0 in models/protocol.go and models/images.go, allows attackers to execute arbitrary code.
- CVE-2022-388701 PoCFree5gc v3.2.1 is vulnerable to Information disclosure.
- CVE-2022-388901 PoCNginx NJS v0.7.7 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h
- CVE-2022-389281 PoCXPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
- CVE-2022-389311 PoCA Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the…
- CVE-2022-389321 PoCreadelf in ToaruOS 2.0.1 has a global overflow allowing RCE when parsing a crafted ELF file.
- CVE-2022-389341 PoCreadelf in ToaruOS 2.0.1 has some arbitrary address read vulnerabilities when parsing a crafted ELF file.
- CVE-2022-389351 PoCAn issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and…
- CVE-2022-389361 PoCAn issue has been found in PBC through 2022-8-27. A SEGV issue detected in the function pbc_wmessage_integer in src/wmessage.c:137.
- CVE-2022-389701 PoCieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices…