CVE-2022-39000 to CVE-2022-39999
49 CVEs with public proof-of-concept exploits.
- CVE-2022-390281 PoCtelnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or…
- CVE-2022-390451 PoCA file write vulnerability exists in the httpd upload.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted…
- CVE-2022-390481 PoCCross-Site Scripting (XSS) vulnerability in ServiceNow UI page assessment_redirect
- CVE-2022-390661 PoCThere is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface,…
- CVE-2022-390731 PoCThere is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use…
- CVE-2022-391721 PoCA stored XSS in the process overview (bersicht zugewiesener Vorgaenge) in mbsupport openVIVA c2 20220101 allows a remote, authenticated,…
- CVE-2022-391731 PoCIn wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly…
- CVE-2022-391952 PoCsA cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML…
- CVE-2022-391961 PoCBlackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly…
- CVE-2022-3919710 PoCsKEVAn XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute…
- CVE-2022-392131 PoCOut-of-bounds Read in go-cvss
- CVE-2022-392221 PoCOAuth authorization code exposure in Dex
- CVE-2022-392273 PoCsPython-jwt subject to Authentication Bypass by Spoofing
- CVE-2022-392531 PoCGit subject to exposure of sensitive information via local clone of symbolic links
- CVE-2022-392581 PoCmailcow-dockerized critical information misrepresentation can lead to phishing attacks through Swagger UI
- CVE-2022-392621 PoCStored Cross-Site Scripting (XSS) on login page in GLPI
- CVE-2022-392741 PoCBuffer Overflow in `ProcessRadioRxDone` in LoRaMac-node
- CVE-2022-392751 PoCImproper object type validation in saleor
- CVE-2022-392761 PoCBlind Server-Side Request Forgery (SSRF) in RSS feeds and planning
- CVE-2022-392771 PoCCross-Site Scripting (XSS) in external links in GLPI
- CVE-2022-392851 PoCStored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
- CVE-2022-392901 PoCCSRF key bypass using HTTP methods in zoneminder
- CVE-2022-392911 PoCDenial of service through logs in zoneminder
- CVE-2022-392991 PoCSignature bypass via multiple root elements in Passport-SAML
- CVE-2022-393051 PoCGin-vue-admin vulnerable to Unrestricted Upload of File with Dangerous Type
- CVE-2022-394251 PoCVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are…
- CVE-2022-398021 PoCSAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request…
- CVE-2022-398111 PoCItaltel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and…
- CVE-2022-398121 PoCItaltel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can…
- CVE-2022-398131 PoCItaltel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via the j_username…
- CVE-2022-398181 PoCIn NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET…
- CVE-2022-398201 PoCIn Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under…
- CVE-2022-398221 PoCIn NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP…
- CVE-2022-398241 PoCServer-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server…
- CVE-2022-398311 PoCAn issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in…
- CVE-2022-398321 PoCAn issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c,…
- CVE-2022-398331 PoCFileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported…
- CVE-2022-398362 PoCsAn issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a…
- CVE-2022-398372 PoCsAn issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a…
- CVE-2022-398391 PoCCotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post.
- CVE-2022-398401 PoCCotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM).
- CVE-2022-399527 PoCsA external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through…
- CVE-2022-399591 PoCPanini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to…
- CVE-2022-399601 PoCThe Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated…
- CVE-2022-399741 PoCWASM3 v0.5.0 was discovered to contain a segmentation fault via the component op_Select_i32_srs in wasm3/source/m3_exec.h.
- CVE-2022-399865 PoCsA Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id…
- CVE-2022-399881 PoCA cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML via a crafted…
- CVE-2022-399961 PoCCross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter…
- CVE-2022-399971 PoCA weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges