CVE-2022-3000 to CVE-2022-3999
367 CVEs with public proof-of-concept exploits.
- CVE-2022-30001 PoCCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm
- CVE-2022-30021 PoCCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm
- CVE-2022-30041 PoCCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm
- CVE-2022-30051 PoCCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm
- CVE-2022-30081 PoCCommand Injection on tinygltf
- CVE-2022-30161 PoCUse After Free in vim/vim
- CVE-2022-30171 PoCCross-Site Request Forgery (CSRF) in froxlor/froxlor
- CVE-2022-30211 PoCSlickr Flickr <= 2.8.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-30241 PoCSimple Bitcoin Faucets <= 1.7.0 - Unauthorised AJAX Call to Stored XSS
- CVE-2022-30251 PoCBitcoin / Altcoin Faucet <= 1.6.0 - Settings Update to Stored XSS via CSRF
- CVE-2022-30351 PoCCross-site Scripting (XSS) - Stored in snipe/snipe-it
- CVE-2022-30361 PoCGettext override translations < 2.0.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-30371 PoCUse After Free in vim/vim
- CVE-2022-30622 PoCsSimple File List < 4.4.12 - Reflected Cross-Site Scripting
- CVE-2022-30651 PoCImproper Access Control in jgraph/drawio
- CVE-2022-30681 PoCImproper Privilege Management in octoprint/octoprint
- CVE-2022-30691 PoCWordlift < 3.37.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-30701 PoCGenerate PDF using Contact Form 7 < 3.6 - Admin+ Stored Cross-Site Scripting
- CVE-2022-30721 PoCCross-site Scripting (XSS) - Stored in francoisjacquet/rosariosis
- CVE-2022-30741 PoCSlider Hero < 8.4.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-30761 PoCCM Download Manager < 2.8.6 - Admin+ Arbitrary File Upload
- CVE-2022-30821 PoCminiOrange Discord Integration < 2.1.6 - Subscriber+ App Disabling
- CVE-2022-30961 PoCWP Total Hacks <= 4.7.2 - Subscriber+ Arbitrary Options Update to Stored XSS
- CVE-2022-30971 PoCLBStopAttack < 1.1.3 - Arbitrary Settings Update via CSRF
- CVE-2022-30981 PoCLogin Block IPs <= 1.0.0 - Arbitrary Setting Update via CSRF
- CVE-2022-30991 PoCUse After Free in vim/vim
- CVE-2022-31131 PoCAn issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in…
- CVE-2022-31191 PoCOAuth client Single Sign On for WordPress < 3.0.4 - Unauthenticated Settings Update to Authentication Bypass
- CVE-2022-31231 PoCCross-site Scripting (XSS) - Reflected in splitbrain/dokuwiki
- CVE-2022-31242 PoCsFrontend File Manager < 21.3 - Unauthenticated File Renaming
- CVE-2022-31251 PoCFrontend File Manager < 21.3 - Subscriber+ Arbitrary File Upload
- CVE-2022-31261 PoCFrontend File Manager < 21.4 - File Upload via CSRF
- CVE-2022-31271 PoCCross-site Scripting (XSS) - Stored in jgraph/drawio
- CVE-2022-31281 PoCDonation Thermometer < 2.1.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-31291 PoCcodeprojects Online Driving School registration.php unrestricted upload
- CVE-2022-31301 PoCcodeprojects Online Driving School login.php sql injection
- CVE-2022-31311 PoCSearch Logger <= 0.9 - Admin+ SQLi
- CVE-2022-31321 PoCGoolytics - Simple Google Analytics < 1.1.2 - Admin+ Stored Cross-Site Scripting
- CVE-2022-31331 PoCOS Command Injection in jgraph/drawio
- CVE-2022-31341 PoCUse After Free in vim/vim
- CVE-2022-31351 PoCSEO Smart Links <= 3.0.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-31361 PoCSocial Rocket < 1.3.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-31371 PoCTaskBuilder < 1.0.8 - Subscriber+ Stored XSS via SVG file upload
- CVE-2022-31381 PoCCross-site Scripting (XSS) - Generic in jgraph/drawio
- CVE-2022-31391 PoCWe’re Open! < 1.42 - Admin+ Stored Cross-Site Scripting
- CVE-2022-31414 PoCsTranslatepress Multilinugal < 2.3.3 - Admin+ SQLi
- CVE-2022-31424 PoCsNEX-Forms < 7.9.7 - Authenticated SQLi
- CVE-2022-31481 PoCCross-site Scripting (XSS) - Generic in jgraph/drawio
- CVE-2022-31491 PoCWP Custom Cursors < 3.0.1 - Stored Cross-Site Scripting via CSRF
- CVE-2022-31501 PoCWP Custom Cursors < 3.2 - Admin+ SQLi
- CVE-2022-31511 PoCWP Custom Cursors < 3.0.1 - Arbitrary Cursor Deletion via CSRF
- CVE-2022-31521 PoCUnverified Password Change in phpfusion/phpfusion
- CVE-2022-31531 PoCNULL Pointer Dereference in vim/vim
- CVE-2022-31541 PoCMultiple Plugins from Viszt Peter - Multiple CSRF
- CVE-2022-31671 PoCImproper Restriction of Rendered UI Layers or Frames in ikus060/rdiffweb
- CVE-2022-31721 PoCKubernetes - API server - Aggregated API server can cause clients to be redirected (SSRF)
- CVE-2022-31731 PoCImproper Authentication in snipe/snipe-it
- CVE-2022-31741 PoCSensitive Cookie in HTTPS Session Without 'Secure' Attribute in ikus060/rdiffweb
- CVE-2022-31751 PoCMissing Custom Error Page in ikus060/rdiffweb
- CVE-2022-31781 PoCBuffer Over-read in gpac/gpac
- CVE-2022-31791 PoCWeak Password Requirements in ikus060/rdiffweb
- CVE-2022-31941 PoCDokan < 3.6.4 - Vendor Stored Cross-Site Scripting
- CVE-2022-32061 PoCPassster < 3.5.5.5.2 - Insecure Storage of Password
- CVE-2022-32071 PoCSimple File List < 4.4.12 - Admin+ Stored Cross-Site Scripting
- CVE-2022-32081 PoCSimple File List < 4.4.13 - Page Creation via CSRF
- CVE-2022-32091 PoCSoledad < 8.2.5 - Reflected Cross-site Scripting
- CVE-2022-32111 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2022-32121 PoCDoS in axum-core due to missing request size limit
- CVE-2022-32161 PoCNintendo Game Boy Color Mobile Adapter GB Tetsuji memory corruption
- CVE-2022-32171 PoCWhen logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate login messages. An…
- CVE-2022-32186 PoCsNecta WiFi Mouse (Mouse Server) client-side authentication bypass
- CVE-2022-32201 PoCAdvanced Comment Form < 1.2.1 - Admin+ Authenticated Stored XSS
- CVE-2022-32211 PoCCross-Site Request Forgery (CSRF) in ikus060/rdiffweb
- CVE-2022-32221 PoCUncontrolled Recursion in gpac/gpac
- CVE-2022-32231 PoCCross-site Scripting (XSS) - Stored in jgraph/drawio
- CVE-2022-32241 PoCMisinterpretation of Input in ionicabizau/parse-url
- CVE-2022-32291 PoCBecause the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote,…
- CVE-2022-32311 PoCCross-site Scripting (XSS) - Stored in librenms/librenms
- CVE-2022-32321 PoCCross-Site Request Forgery (CSRF) in ikus060/rdiffweb
- CVE-2022-32331 PoCCross-Site Request Forgery (CSRF) in ikus060/rdiffweb
- CVE-2022-32341 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-32351 PoCUse After Free in vim/vim
- CVE-2022-32361 PoCKEVA code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0…
- CVE-2022-32371 PoCWP Contact Slider < 2.4.8 - Admin+ Stored Cross-Site Scripting
- CVE-2022-32411 PoCBuild App Online < 1.0.19 - Unauthenticated SQL Injection
- CVE-2022-32422 PoCsHTML code Injection in template search keyword in microweber/microweber
- CVE-2022-32431 PoCImport all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLi
- CVE-2022-32451 PoCCode Injection in display of tag title on saving tags in microweber/microweber
- CVE-2022-32461 PoCBlog2Social < 6.9.10 - Subscriber+ SQLi
- CVE-2022-32471 PoCBlog2Social < 6.9.10 - Subscriber+ SSRF
- CVE-2022-32491 PoCWP CSV Exporter < 1.3.7 - Admin+ SQLi
- CVE-2022-32501 PoCSensitive Cookie in HTTPS Session Without 'Secure' Attribute in ikus060/rdiffweb
- CVE-2022-32511 PoCSensitive Cookie in HTTPS Session Without 'Secure' Attribute in ikus060/minarca
- CVE-2022-32542 PoCsAWP Classifieds Plugin < 4.3 - Unauthenticated SQLi
- CVE-2022-32551 PoCCross-site Scripting (XSS) - Reflected in pimcore/pimcore
- CVE-2022-32561 PoCUse After Free in vim/vim
- CVE-2022-32671 PoCCross-Site Request Forgery (CSRF) in ikus060/rdiffweb
- CVE-2022-32681 PoCWeak Password Requirements in ikus060/minarca
- CVE-2022-32691 PoCSession Fixation in ikus060/rdiffweb
- CVE-2022-32721 PoCImproper Handling of Length Parameter Inconsistency in ikus060/rdiffweb
- CVE-2022-32731 PoCAllocation of Resources Without Limits or Throttling in ikus060/rdiffweb
- CVE-2022-32741 PoCCross-Site Request Forgery (CSRF) on user's settings in GitHub repository ikus060/rdiffweb prior to 2.4.6. in ikus060/rdiffweb
- CVE-2022-32781 PoCNULL Pointer Dereference in vim/vim
- CVE-2022-32821 PoCDrag and Drop Multiple File Upload < 1.3.6.5 - File Upload Size Limit Bypass
- CVE-2022-32901 PoCImproper Handling of Length Parameter Inconsistency in ikus060/rdiffweb
- CVE-2022-32921 PoCUse of Cache Containing Sensitive Information in ikus060/rdiffweb
- CVE-2022-32951 PoCAllocation of Resources Without Limits or Throttling in ikus060/rdiffweb
- CVE-2022-32961 PoCStack-based Buffer Overflow in vim/vim
- CVE-2022-32971 PoCUse After Free in vim/vim
- CVE-2022-32981 PoCAllocation of Resources Without Limits or Throttling in ikus060/rdiffweb
- CVE-2022-33001 PoCForm Maker by 10Web < 1.15.6 - Admin+ SQLI
- CVE-2022-33011 PoCImproper Cleanup on Thrown Exception in ikus060/rdiffweb
- CVE-2022-33021 PoCAnti-Spam by CleanTalk < 5.185.1 - Admin+ SQLi
- CVE-2022-33031 PoCA race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference…
- CVE-2022-33231 PoCAn SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which…
- CVE-2022-33241 PoCStack-based Buffer Overflow in vim/vim
- CVE-2022-33261 PoCWeak Password Requirements in ikus060/rdiffweb
- CVE-2022-33281 PoCRace condition in snap-confine's must_mkdir_and_open_with_perms()
- CVE-2022-33331 PoCZephyr Project Manager REST Call cross site scripting
- CVE-2022-33341 PoCEasy WP SMTP < 1.5.0 - Admin+ PHP Objection Injection
- CVE-2022-33351 PoCKadence WooCommerce Email Designer < 1.5.7 - Admin+ PHP Objection Injection
- CVE-2022-33361 PoCEvent Monster < 1.2.0 - Visitors Deletion via CSRF
- CVE-2022-33431 PoCWPQA < 5.9.3 - Missing validation lead to functionality abuse
- CVE-2022-33491 PoCSony PS4/PS5 exFAT UVFAT_readupcasetable heap-based overflow
- CVE-2022-33501 PoCContact Bank <= 3.0.30 - Admin+ Stored Cross-Site Scripting
- CVE-2022-33521 PoCUse After Free in vim/vim
- CVE-2022-33551 PoCCross-site Scripting (XSS) - Stored in inventree/inventree
- CVE-2022-33572 PoCsSmart Slider 3 < 3.5.1.11 - PHP Object Injection
- CVE-2022-33591 PoCShortcodes and extra features for Phlox theme < 2.10.7 - PHP Objection Injection
- CVE-2022-33601 PoCLearnPress < 4.1.7.2 - Unauthenticated PHP Object Injection via REST API
- CVE-2022-33621 PoCInsufficient Session Expiration in ikus060/rdiffweb
- CVE-2022-33641 PoCNo limit in length of "Fullname" parameter results in DOS attack /memory corruption in ikus060/rdiffweb prior to 2.5.0a3 in ikus060/rdiffweb
- CVE-2022-33651 PoCEmote Interactive Remote Mouse Server command injection due to weak encoding
- CVE-2022-33661 PoCPublishPress Capabilities < 2.5.2 - Admin+ PHP Objection Injection
- CVE-2022-33681 PoCSoftware Updater of Avira Security for Windows vulnerable to Privilege Escalation
- CVE-2022-33711 PoCNo limit in length of "Token name" parameter results in DOS attack /memory corruption in ikus060/rdiffweb prior to 2.5.0a3 in…
- CVE-2022-33741 PoCOcean Extra < 2.0.5 - Admin+ PHP Objection Injection
- CVE-2022-33761 PoCWeak Password Requirements in ikus060/rdiffweb
- CVE-2022-33801 PoCCustomizer Export/Import < 0.9.5 - Admin+ PHP Objection Injection
- CVE-2022-33891 PoCPath Traversal in ikus060/rdiffweb
- CVE-2022-33911 PoCRetain Live Chat <= 0.1 - Admin+ Stored Cross-Site Scripting
- CVE-2022-33921 PoCWP Humans.txt <= 1.0.6 - Admin+ Stored Cross-Site Scripting
- CVE-2022-33931 PoCPost to CSV by BestWebSoft <= 1.4.0 - Author+ CSV Injection
- CVE-2022-33941 PoCWP All Export Pro < 1.7.9 - Authenticated Code Injection
- CVE-2022-33951 PoCWP All Export Pro < 1.7.9 - Authenticated SQLi
- CVE-2022-34052 PoCsCode execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are…
- CVE-2022-34081 PoCWP Word Count <= 3.2.3 - Admin+ Stored Cross-Site Scripting
- CVE-2022-34151 PoCChat Bubble < 2.3 - Unauthenticated Stored Cross-Site Scripting
- CVE-2022-34161 PoCWPtouch < 4.3.45 - Admin+ Arbitrary File Upload
- CVE-2022-34171 PoCWPtouch < 4.3.45 - Admin+ PHP Object Injection
- CVE-2022-34181 PoCWP All Import < 3.6.9 - Admin+ Arbitrary File Upload to RCE
- CVE-2022-34191 PoCAutomatic User Roles Switcher < 1.1.2 - Subscriber+ Privilege Escalation
- CVE-2022-34201 PoCOfficial Integration for Billingo < 3.4.0 - ShopManager+ Stored XSS
- CVE-2022-34221 PoCImproper Privilege Management in tooljet/tooljet
- CVE-2022-34231 PoCAllocation of Resources Without Limits or Throttling in nocodb/nocodb
- CVE-2022-34251 PoCGoogle Analyticator < 6.5.6 - Admin+ PHP Object Injection
- CVE-2022-34261 PoCAdvanced WP Columns <= 2.0.6 - Admin+ Stored Cross-Site Scripting
- CVE-2022-34361 PoCSourceCodester Web-Based Student Clearance System Photo edit-photo.php unrestricted upload
- CVE-2022-34381 PoCOpen Redirect in ikus060/rdiffweb
- CVE-2022-34401 PoCRock Convert < 2.6.0 - Reflected Cross-Site Scripting
- CVE-2022-34411 PoCRock Convert < 2.11.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-34421 PoCCrealogix EBICS ebics.aspx cross site scripting
- CVE-2022-34511 PoCProduct Stock Manager < 1.0.5 - Subscriber+ Unauthorised AJAX Calls
- CVE-2022-34621 PoCHighlight Focus <= 1.1 - Admin+ Stored Cross Site Scripting
- CVE-2022-34631 PoCFluentForm < 4.3.13 - CSV Injection
- CVE-2022-34641 PoCpuppyCMS settings.php cross site scripting
- CVE-2022-34691 PoCWP Attachments < 5.0.5 - Admin+ Stored Cross-Site Scripting
- CVE-2022-34701 PoCSourceCodester Human Resource Management System getstatecity.php sql injection
- CVE-2022-34711 PoCSourceCodester Human Resource Management System city.php sql injection
- CVE-2022-34721 PoCSourceCodester Human Resource Management System city.php sql injection
- CVE-2022-34731 PoCSourceCodester Human Resource Management System getstatecity.php sql injection
- CVE-2022-34772 PoCstagDiv Composer < 3.5 - Unauthenticated Account Takeover
- CVE-2022-34812 PoCsWooCommerce Dropshipping < 4.4 - Unauthenticated SQLi
- CVE-2022-34842 PoCsWPB Show Core - Reflected Cross-Site Scripting
- CVE-2022-34891 PoCWP Hide <= 0.0.2 - Unauthenticated Settings Update
- CVE-2022-34901 PoCCheckout Field Editor for WooCommerce < 1.8.0 - Admin+ PHP Object Injection
- CVE-2022-34911 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-34941 PoCComplianz (Free < 6.3.4, Premium < 6.3.6) - Translator SQLi
- CVE-2022-34951 PoCSourceCodester Simple Online Public Access Catalog Admin Login sql injection
- CVE-2022-35021 PoCHuman Resource Management System Leave cross site scripting
- CVE-2022-35031 PoCSourceCodester Purchase Order Management System Supplier cross site scripting
- CVE-2022-35062 PoCsCross-site Scripting (XSS) - Stored in barrykooij/related-posts-for-wp
- CVE-2022-35111 PoCAwesome Support < 6.1.2 - Subscriber+ Arbitrary Exported Tickets Download
- CVE-2022-35141 PoCAn issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6…
- CVE-2022-35181 PoCSourceCodester Sanitization Management System User Creation cross site scripting
- CVE-2022-35201 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-35361 PoCRole Based Pricing for WooCommerce < 1.6.3 - Subscriber+ PHAR Deserialization
- CVE-2022-35371 PoCRole Based Pricing for WooCommerce < 1.6.2 - Subscriber+ Arbitrary File Upload
- CVE-2022-35381 PoCWebmaster Tools Verification <= 1.2 - Unauthenticated Arbitrary Plugin Deactivation
- CVE-2022-35391 PoCTestimonials (Free < 2.7, Pro < 1.0.8) - Admin+ Stored Cross-Site Scripting
- CVE-2022-35462 PoCsSourceCodester Simple Cold Storage Management System Create User cross site scripting
- CVE-2022-35471 PoCSourceCodester Simple Cold Storage Management System Setting cross site scripting
- CVE-2022-35481 PoCSourceCodester Simple Cold Storage Management System Add New Storage cross site scripting
- CVE-2022-35525 PoCsUnrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
- CVE-2022-35581 PoCImport and export users and customers < 1.20.5 - Subscriber+ CSV Injection
- CVE-2022-35641 PoCLinux Kernel Bluetooth l2cap_core.c l2cap_reassemble_sdu use after free
- CVE-2022-35692 PoCsDue to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in…
- CVE-2022-35702 PoCsMultiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds…
- CVE-2022-35741 PoCWPForms Pro < 1.7.7 - CSV Injection
- CVE-2022-35782 PoCsProfileGrid < 5.1.1 - Reflected Cross-Site Scripting
- CVE-2022-35791 PoCSourceCodester Cashier Queuing System Login Page login.php sql injection
- CVE-2022-35821 PoCSourceCodester Simple Cold Storage Management System cross-site request forgery
- CVE-2022-35831 PoCSourceCodester Canteen Management System login.php sql injection
- CVE-2022-35841 PoCSourceCodester Canteen Management System edituser.php sql injection
- CVE-2022-35851 PoCSourceCodester Simple Cold Storage Management System Contact Us cross-site request forgery
- CVE-2022-35871 PoCSourceCodester Simple Cold Storage Management System My Account cross site scripting
- CVE-2022-35903 PoCsWP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding
- CVE-2022-35971 PoCLibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection,…
- CVE-2022-35981 PoCLibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a…
- CVE-2022-35991 PoCLibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service…
- CVE-2022-36001 PoCEasy Digital Downloads < 3.1.0.2 - Unauthenticated CSV Injection
- CVE-2022-36011 PoCImage Hover Effects Css3 <= 4.5 - Admin+ Stored XSS
- CVE-2022-36029 PoCsX.509 Email Address 4-byte Buffer Overflow
- CVE-2022-36031 PoCExport customers list CSV for WooCommerce < 2.0.69 - CSV Injection
- CVE-2022-36041 PoCContact Form Entries < 1.3.0 - CSV Injection
- CVE-2022-36051 PoCWP CSV Exporter < 1.3.7 - CSV Injection
- CVE-2022-36081 PoCCross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
- CVE-2022-36091 PoCGetYourGuide Ticketing < 1.0.4 - Admin+ Stored XSS
- CVE-2022-36101 PoCJeeng Push Notifications < 2.0.4 - Admin+ Stored Cross-Site Scripting
- CVE-2022-36181 PoCSpacer < 3.0.7 - Admin+ Stored XSS
- CVE-2022-36261 PoCLibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections,…
- CVE-2022-36311 PoCOAuth Client by DigitialPixies <= 1.1.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-36321 PoCOAuth Client by DigitialPixies <= 1.1.0 - CSRF
- CVE-2022-36341 PoCContact Form 7 Database Addon < 1.2.6.5 - CSV Injection
- CVE-2022-36501 PoCA privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a…
- CVE-2022-36531 PoCHeap buffer overflow in Vulkan in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption…
- CVE-2022-36561 PoCInsufficient data validation in File System in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass file system…
- CVE-2022-36621 PoCAxiomatic Bento4 mp42hls Ap4Sample.h GetOffset use after free
- CVE-2022-36631 PoCAxiomatic Bento4 MP4fragment Ap4StsdAtom.cpp AP4_StsdAtom null pointer dereference
- CVE-2022-36641 PoCAxiomatic Bento4 avcinfo Ap4BitStream.cpp WriteBytes heap-based overflow
- CVE-2022-36651 PoCAxiomatic Bento4 avcinfo AvcInfo.cpp heap-based overflow
- CVE-2022-36661 PoCAxiomatic Bento4 mp42ts Ap4LinearReader.cpp Advance use after free
- CVE-2022-36681 PoCAxiomatic Bento4 mp4edit CreateAtomFromStream memory leak
- CVE-2022-36691 PoCAxiomatic Bento4 mp4edit Create memory leak
- CVE-2022-36701 PoCAxiomatic Bento4 mp42hevc WriteSample heap-based overflow
- CVE-2022-36711 PoCSourceCodester eLearning System manage.php sql injection
- CVE-2022-36771 PoCAdvanced Import < 1.3.8 - Arbitrary Plugin Installation & Activation via CSRF
- CVE-2022-36791 PoCStarter Templates by Kadence WP < 1.2.17 - Admin+ PHP Object Injection
- CVE-2022-36881 PoCWPQA < 5.9 - Follow/Unfollow via CSRF
- CVE-2022-36893 PoCsHTML Forms < 1.3.25 - Admin+ SQLi
- CVE-2022-36901 PoCPopup Maker < 1.16.11 - Contributor+ Stored Cross Site Scripting
- CVE-2022-36911 PoCDeepL Pro API Translation < 1.7.5 - API Key Disclosure
- CVE-2022-36941 PoCSyncee - Global Dropshipping < 1.0.10 - Authentication Token Disclosure
- CVE-2022-36995 PoCsA privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior…
- CVE-2022-37041 PoCRuby on Rails _table.html.erb cross site scripting
- CVE-2022-37201 PoCEvent Monster < 1.2.1 - Admin+ SQLi
- CVE-2022-37231 PoCKEVType confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2022-37251 PoCCrash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file
- CVE-2022-37391 PoCWP Best Quiz <= 1.0 - Author+ Stored XSS
- CVE-2022-37411 PoCImproper Restriction of Excessive Authentication Attempts in chatwoot/chatwoot
- CVE-2022-37471 PoCBecustom <= 1.0.5.2 - Cross-Site Request Forgery
- CVE-2022-37501 PoCAsk Me < 6.8.7 - Post Deletion via CSRF
- CVE-2022-37531 PoCEvaluate <= 1.0 - Admin+ Stored Cross-Site Scripting
- CVE-2022-37541 PoCWeak Password Requirements in thorsten/phpmyfaq
- CVE-2022-37621 PoCBooster for WooCommerce - ShopManager+ Arbitrary File Download
- CVE-2022-37631 PoCBooster for WooCommerce - Checkout Files Deletion via CSRF
- CVE-2022-37641 PoCForm Vibes < 1.4.5 - Admin+ SQLi
- CVE-2022-37651 PoCCross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
- CVE-2022-37663 PoCsCross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
- CVE-2022-37683 PoCsWPSmartContracts < 1.3.12 - Author+ SQLi
- CVE-2022-37692 PoCsOWM Weather < 5.6.9 - Contributor+ SQLi
- CVE-2022-37743 PoCsSourceCodester Train Scheduler App resource injection
- CVE-2022-37821 PoCkeycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a…
- CVE-2022-37841 PoCAxiomatic Bento4 mp4hls Ap4Mp4AudioInfo.cpp ReadBits heap-based overflow
- CVE-2022-37851 PoCAxiomatic Bento4 Avcinfo SetDataSize heap-based overflow
- CVE-2022-37865 PoCsX.509 Email Address Variable Length Buffer Overflow
- CVE-2022-37922 PoCsSQL Injection in GullsEye Terminal Operating System
- CVE-2022-38001 PoCIBAX go-ibax rowsInfo sql injection
- CVE-2022-38051 PoCJeg Elementor Kit <= 2.5.6 - Unauthenticated Authorization Bypass
- CVE-2022-38091 PoCAxiomatic Bento4 mp4tag Mp4Tag.cpp ParseCommandLine denial of service
- CVE-2022-38101 PoCAxiomatic Bento4 mp42hevc Mp42Hevc.cpp AP4_File denial of service
- CVE-2022-38111 PoCEU Cookie Law <= 3.1.6 - Admin+ Stored XSS
- CVE-2022-38121 PoCAxiomatic Bento4 mp4encrypt AP4_ContainerAtom memory leak
- CVE-2022-38141 PoCAxiomatic Bento4 mp4decrypt memory leak
- CVE-2022-38151 PoCAxiomatic Bento4 mp4decrypt memory leak
- CVE-2022-38161 PoCAxiomatic Bento4 mp4decrypt memory leak
- CVE-2022-38171 PoCAxiomatic Bento4 mp4mux memory leak
- CVE-2022-38221 PoCDonations via PayPal < 1.9.9 - Admin+ Stored XSS
- CVE-2022-38231 PoCBeautiful Cookie Consent Banner < 2.9.1 - Admin+ Stored XSS
- CVE-2022-38241 PoCWP Admin UI Customize < 1.5.13 - Admin+ Stored XSS
- CVE-2022-38281 PoCVideo Thumbnails <= 2.12.3 - Admin+ Stored XSS
- CVE-2022-38291 PoCFont Awesome 4 Menus <= 4.7.0 - Admin+ Stored XSS
- CVE-2022-38301 PoCWP Page Builder <= 1.2.8 - Admin+ Stored Cross-Site
- CVE-2022-38311 PoCreCAPTCHA <= 1.6 - Admin+ Stored XSS
- CVE-2022-38321 PoCExternal Media < 1.0.36 - Admin+ Stored XSS
- CVE-2022-38331 PoCFancier Author Box by ThematoSoup <= 1.4 - Admin+ Stored XSS
- CVE-2022-38341 PoCGoogle Forms <= 0.95 - Admin+ Stored XSS
- CVE-2022-38351 PoCKwayy HTML Sitemap < 4.0 - Admin+ Stored XSS
- CVE-2022-38361 PoCSeed Social < 2.0.4 - Admin+ Stored XSS
- CVE-2022-38371 PoCUji Countdown < 2.3.1 - Admin+ Stored XSS
- CVE-2022-38381 PoCWPUpper Share Buttons <= 3.42 - Admin+ Stored XSS
- CVE-2022-38391 PoCAnalytics for WP <= 1.5.1 - Admin+ Stored XSS
- CVE-2022-38401 PoCGoogle Apps Login < 3.4.5 - Admin+ Stored XSS
- CVE-2022-38461 PoCWorkreap - Freelance Marketplace and Directory < 2.6.3 - Subscriber+ Private Message Disclosure via IDOR
- CVE-2022-38472 PoCsShowing URL in QR Code <= 0.0.1 - Stored XSS via CSRF
- CVE-2022-38482 PoCsWP User Merger < 1.5.3 - Admin+ SQLi via wpsu_user_id
- CVE-2022-38492 PoCsWP User Merger < 1.5.3 - Admin+ SQLi via user_id
- CVE-2022-38501 PoCFind and Replace All <= 1.3 - Arbitrary Replacement via CSRF
- CVE-2022-38531 PoCSupra CSV <= 4.0.3 - Stored Cross-Site Scripting via CSRF
- CVE-2022-38551 PoC404 to Start <= 1.6.1 - Admin+ Stored XSS
- CVE-2022-38561 PoCComic Book Management System < 2.2.0 - Admin+ SQLi
- CVE-2022-38581 PoCChaty < 3.0.3 - Admin+ SQLi
- CVE-2022-38601 PoCVisual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLi
- CVE-2022-38611 PoCBetheme <= 26.5.1.4 - Authenticated (Subscriber+) PHP Object Injection
- CVE-2022-38621 PoCLivemesh Addons for Elementor < 7.2.4 - Admin+ Stored XSS
- CVE-2022-38652 PoCsWP User Merger < 1.5.3 - Admin+ SQLi via ID
- CVE-2022-38692 PoCsCode Injection in froxlor/froxlor
- CVE-2022-38731 PoCCross-site Scripting (XSS) - DOM in jgraph/drawio
- CVE-2022-38751 PoCClick Studios Passwordstate API authentication bypass by assumed-immutable data
- CVE-2022-38761 PoCClick Studios Passwordstate API authorization
- CVE-2022-38771 PoCClick Studios Passwordstate URL Field cross site scripting
- CVE-2022-38791 PoCCar Dealer < 3.05 - Subscriber+ Arbitrary Plugin Installation
- CVE-2022-38801 PoCAntiHacker < 4.20 - Subscriber+ Arbitrary Plugin Installation
- CVE-2022-38811 PoCWPTools < 3.43 - Subscriber+ Arbitrary Plugin Installation
- CVE-2022-38821 PoCWP Memory < 2.46 - Subscriber+ Arbitrary Plugin Installation
- CVE-2022-38831 PoCStopBadBots < 7.24 - Subscriber+ Arbitrary Plugin Installation
- CVE-2022-38911 PoCWP FullCalendar < 1.5 - Unauthenticated Arbitrary Post Access
- CVE-2022-38921 PoCWP OAuth Server < 4.2.2 - Admin+ Stored XSS
- CVE-2022-38941 PoCWP OAuth Server < 4.2.5 - Arbitrary Post Deletion via CSRF
- CVE-2022-38991 PoC3DPrint < 3.5.6.9 - Arbitrary File and Directory Deletion via CSRF
- CVE-2022-39001 PoCCooked Pro < 1.7.5.7 - Unauthenticated PHP Object Injection
- CVE-2022-39042 PoCsMonsterInsights < 8.9.1 - Stored Cross-Site Scripting via Google Analytics
- CVE-2022-39061 PoCEasy Form Builder < 3.4.0 - Admin+ Stored XSS
- CVE-2022-39071 PoCClerk < 4.0.0 - Authentication Bypass and API Keys Disclosure
- CVE-2022-39082 PoCsHelloprint < 1.4.7 - Reflected Cross-Site Scripting
- CVE-2022-39091 PoCAdd Comments <= 1.0.1 - Admin+ Stored XSS
- CVE-2022-39102 PoCsUse after free in IO_uring in the Linux Kernel
- CVE-2022-39111 PoCiubenda < 3.3.3 - Subscriber+ Privileges Escalation to Admin
- CVE-2022-39121 PoCUser Registration < 2.2.4.1 - Subscriber+ Arbitrary File Upload
- CVE-2022-39151 PoCDokan < 3.7.6 - Unauthenticated SQLi
- CVE-2022-39191 PoCJetpack CRM < 5.4.3 - Admin+ Cross-Site Scripting
- CVE-2022-39211 PoCListingo < 3.2.7 - Unauthenticated Arbitrary File Upload
- CVE-2022-39221 PoCBroken Link Checker < 1.11.20 - Admin+ Cross-Site Scripting
- CVE-2022-39231 PoCActiveCampaign for WooCommerce < 1.9.8 - Subscriber+ Error Log Cleanup
- CVE-2022-39251 PoCBuddybadges <= 1.0.0 - Admin+ SQLi
- CVE-2022-39261 PoCWP OAuth Server < 3.4.2 - Client Secret Regeneration via CSRF
- CVE-2022-39301 PoCDirectorist < 7.4.2.2 - Subscriber+ Arbitrary User Password Update via IDOR
- CVE-2022-39332 PoCsEssential Real Estate < 3.9.6 - Reflected Cross-Site-Scripting
- CVE-2022-39342 PoCsFlat PM < 3.0.13 - Reflected Cross-Site Scripting
- CVE-2022-39351 PoCWelcart e-Commerce < 2.8.4 - Multiple Subscriber+ Stored Cross-Site Scripting
- CVE-2022-39361 PoCTeam Members < 5.2.1 - Editor+ Stored XSS
- CVE-2022-39371 PoCEasy Video Player < 1.2.2.3 - Contributor+ Stored XSS
- CVE-2022-39421 PoCSourceCodester Sanitization Management System cross site scripting
- CVE-2022-39441 PoCjerryhanjj ERP Commodity Management inventory.php uploadImages unrestricted upload
- CVE-2022-39451 PoCImproper Restriction of Excessive Authentication Attempts in kareadita/kavita
- CVE-2022-39461 PoCWelcart e-Commerce < 2.8.4 - Subscriber+ Arbitrary Shipping Method Creation/Update/Deletion
- CVE-2022-39491 PoCSourcecodester Simple Cashiering System User Account cross site scripting
- CVE-2022-39551 PoCtholum crm42 Login class.user.php sql injection
- CVE-2022-39561 PoCtsruban HHIMS Patient Portrait sql injection
- CVE-2022-39611 PoCDirectorist < 7.4.4 - Subscriber+ Sensitive Information Disclosure
- CVE-2022-39721 PoCPingkon HMS-PHP adminlogin.php sql injection
- CVE-2022-39731 PoCPingkon HMS-PHP Data Pump Metadata admin.php sql injection
- CVE-2022-39741 PoCAxiomatic Bento4 mp4info Ap4StdCFileByteStream.cpp ReadPartial heap-based overflow
- CVE-2022-39801 PoCAn XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed…
- CVE-2022-39811 PoCIcegram Express < 5.5.1 - Subscriber+ SQLi
- CVE-2022-39823 PoCsBooking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload
- CVE-2022-39831 PoCCheckout for PayPal < 1.0.14 - Contributor+ Stored XSS
- CVE-2022-39841 PoCFlowplayer Video Player < 1.0.5 - Contributor+ Stored XSS
- CVE-2022-39851 PoCVideojs HTML5 Player < 1.1.9 - Contributor+ Stored XSS
- CVE-2022-39861 PoCWP Stripe Checkout < 1.2.2.21 - Contributor+ Stored XSS
- CVE-2022-39871 PoCResponsive Lightbox2 < 1.0.4 - Contributor+ Stored XSS
- CVE-2022-39891 PoCMotors - Car Dealer, Classifieds & Listing < 1.4.4 - Arbitrary File Upload
- CVE-2022-39921 PoCSourceCodester Sanitization Management System Banner Image cross site scripting
- CVE-2022-39931 PoCImproper Restriction of Excessive Authentication Attempts in kareadita/kavita
- CVE-2022-39941 PoCAuthenticator < 1.3.1 - Subscriber+ Denial of Service via Feed Token Disclosure
- CVE-2022-39981 PoCMonikaBrzica scm uredi_korisnika.php sql injection
- CVE-2022-39991 PoCWooCommerce Shipping - DPD baltic < 1.2.57 - Subscriber+ Arbitrary Options Deletion