CVE-2022-40000 to CVE-2022-40999
140 CVEs with public proof-of-concept exploits.
- CVE-2022-400052 PoCsIntelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the…
- CVE-2022-400081 PoCSWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.
- CVE-2022-400091 PoCSWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.
- CVE-2022-400101 PoCTenda AC6 AC1200 Smart Dual-Band WiFi Router 15.03.06.50_multi was discovered to contain a cross-site scripting (XSS) vulnerability via…
- CVE-2022-400161 PoCUse After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in librtmp, allows…
- CVE-2022-400222 PoCsMicrochip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
- CVE-2022-400231 PoCSqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects…
- CVE-2022-400323 PoCsSQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows…
- CVE-2022-400431 PoCCentreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at…
- CVE-2022-400441 PoCCentreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at…
- CVE-2022-400471 PoCFlatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at…
- CVE-2022-400671 PoCTenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetVirtualSer.
- CVE-2022-400681 PoCTenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetQosBand.
- CVE-2022-400691 PoC]Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetSysTime.
- CVE-2022-400701 PoCTenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via bin/httpd, function: formSetFirewallCfg.
- CVE-2022-400711 PoCTenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, formSetDeviceName.
- CVE-2022-400721 PoCTenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: setSmartPowerManagement.
- CVE-2022-400731 PoCTenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, saveParentControlInfo.
- CVE-2022-400741 PoCTenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, setSchedWifi.
- CVE-2022-400751 PoCTenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, form_fast_setting_wifi_set.
- CVE-2022-400761 PoCTenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetWifiGusetBasic.
- CVE-2022-400831 PoCLabstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be…
- CVE-2022-400871 PoCSimple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This…
- CVE-2022-400881 PoCSimple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component…
- CVE-2022-400891 PoCA remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP…
- CVE-2022-400901 PoCAn issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF…
- CVE-2022-401132 PoCsOnline Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds.php.
- CVE-2022-401142 PoCsOnline Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at…
- CVE-2022-401152 PoCsOnline Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at…
- CVE-2022-401162 PoCsOnline Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/beneficiary.php.
- CVE-2022-401172 PoCsOnline Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at…
- CVE-2022-401182 PoCsOnline Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at…
- CVE-2022-401192 PoCsOnline Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at…
- CVE-2022-401202 PoCsOnline Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at…
- CVE-2022-401212 PoCsOnline Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at…
- CVE-2022-401222 PoCsOnline Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at…
- CVE-2022-401231 PoCmojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This…
- CVE-2022-401261 PoCA misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute…
- CVE-2022-401274 PoCsApache Airflow <2.4.0 has an RCE in a bash example
- CVE-2022-401291 PoCA use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted…
- CVE-2022-401462 PoCsJar url should be blocked by DefaultScriptSecurity
- CVE-2022-402201 PoCAn OS command injection vulnerability exists in the httpd txt/restore.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A…
- CVE-2022-402221 PoCAn OS command injection vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A…
- CVE-2022-402241 PoCA denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A…
- CVE-2022-402501 PoCStack overflow vulnerability in SMI handler on SmmSmbiosElog.
- CVE-2022-402822 PoCsThe web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to…
- CVE-2022-402971 PoCUBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four…
- CVE-2022-403021 PoCAn issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended…
- CVE-2022-403051 PoCA Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network…
- CVE-2022-403061 PoCThe login form /Login in ECi Printanista Hub (formerly FMAudit Printscout) before 5.5.2 (July 2023) performs expensive RSA key-generation…
- CVE-2022-403171 PoCOpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
- CVE-2022-403191 PoCThe LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email…
- CVE-2022-403201 PoCcfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.
- CVE-2022-403472 PoCsSQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name'…
- CVE-2022-403481 PoCCross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'email' parameters,…
- CVE-2022-403571 PoCA security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the…
- CVE-2022-403592 PoCsCross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php.
- CVE-2022-403632 PoCsA buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to…
- CVE-2022-404341 PoCSoftr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
- CVE-2022-404351 PoCEmployee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new…
- CVE-2022-404391 PoCAn memory leak issue was discovered in AP4_StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers to cause a denial…
- CVE-2022-404401 PoCmxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
- CVE-2022-404432 PoCsAn absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to…
- CVE-2022-404441 PoCZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.
- CVE-2022-404691 PoCiKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.
- CVE-2022-404702 PoCsPhpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.
- CVE-2022-404714 PoCsRemote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture…
- CVE-2022-404822 PoCsThe authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing…
- CVE-2022-404861 PoCTP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute…
- CVE-2022-404891 PoCThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be…
- CVE-2022-404901 PoCTiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows…
- CVE-2022-404941 PoCNPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key…
- CVE-2022-406191 PoCFunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of…
- CVE-2022-406211 PoCWAVLINK Quantum D4G (WN531G3) Pass-The-Hash
- CVE-2022-406221 PoCWAVLINK Quantum D4G (WN531G3) Session Management by IP Address
- CVE-2022-406231 PoCWAVLINK Quantum D4G (WN531G3) CSRF
- CVE-2022-406242 PoCspfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a…
- CVE-2022-406341 PoCImproper Control of Dynamically-Managed Code Resources in Crafter Studio
- CVE-2022-406351 PoCImproper Control of Dynamically-Managed Code Resources in Crafter Studio
- CVE-2022-4068434 PoCsKEVAn authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through…
- CVE-2022-406911 PoCAn information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch…
- CVE-2022-406931 PoCA cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1.…
- CVE-2022-407011 PoCA directory traversal vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A…
- CVE-2022-407343 PoCsUniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read…
- CVE-2022-407361 PoCAn issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in AP4_CttsAtom::Create in Core/Ap4CttsAtom.cpp.
- CVE-2022-407371 PoCAn issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4_StdcFileByteStream::WritePartial…
- CVE-2022-407381 PoCAn issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_DescriptorListWriter::Action in…
- CVE-2022-407551 PoCJasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.
- CVE-2022-407691 PoCprofanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity…
- CVE-2022-407741 PoCAn issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference in AP4_StszAtom::GetSampleSize.
- CVE-2022-407751 PoCAn issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_StszAtom::WriteFields.
- CVE-2022-407981 PoCOcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request…
- CVE-2022-408391 PoCA SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers…
- CVE-2022-408401 PoCndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via createPdf.php.
- CVE-2022-408411 PoCA cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or…
- CVE-2022-408421 PoCndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
- CVE-2022-408432 PoCsThe Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the…
- CVE-2022-408441 PoCIn Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) issue…
- CVE-2022-408451 PoCThe Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper…
- CVE-2022-408461 PoCIn Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to…
- CVE-2022-408471 PoCIn Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools.…
- CVE-2022-408491 PoCThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could…
- CVE-2022-408511 PoCTenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.
- CVE-2022-408531 PoCTenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set
- CVE-2022-408541 PoCTenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set
- CVE-2022-408551 PoCTenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This…
- CVE-2022-408601 PoCTenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request…
- CVE-2022-408611 PoCTenda AC18 router V15.03.05.19 contains a stack overflow vulnerability in the formSetQosBand->FUN_0007db78 function with the request…
- CVE-2022-408621 PoCTenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request…
- CVE-2022-408641 PoCTenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request…
- CVE-2022-408651 PoCTenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request…
- CVE-2022-408661 PoCTenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function…
- CVE-2022-408671 PoCTenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function…
- CVE-2022-408681 PoCTenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function…
- CVE-2022-408691 PoCTenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined…
- CVE-2022-408711 PoCDolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of…
- CVE-2022-408741 PoCTenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a…
- CVE-2022-408751 PoCTenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.
- CVE-2022-408762 PoCsIn Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack…
- CVE-2022-408771 PoCExam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.
- CVE-2022-408781 PoCIn Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code…
- CVE-2022-408792 PoCskkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'
- CVE-2022-408813 PoCsSolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
- CVE-2022-408871 PoCSourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection.
- CVE-2022-408901 PoCA vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.
- CVE-2022-408961 PoCA ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
- CVE-2022-408971 PoCPython Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted…
- CVE-2022-408981 PoCAn issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via…
- CVE-2022-408991 PoCAn issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted…
- CVE-2022-409121 PoCETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to the GET parameter…
- CVE-2022-409161 PoCTiny File Manager v2.4.7 and below is vulnerable to session fixation.
- CVE-2022-409221 PoCA vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a denial of service…
- CVE-2022-409231 PoCA vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a denial of service…
- CVE-2022-409241 PoCZoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the…
- CVE-2022-409311 PoCdutchcoders Transfer.sh 1.4.0 is vulnerable to Cross Site Scripting (XSS).
- CVE-2022-409441 PoCDairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.
- CVE-2022-409463 PoCsOn D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token…
- CVE-2022-409691 PoCAn os command injection vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A…
- CVE-2022-409821 PoCInformation exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R)…
- CVE-2022-409831 PoCAn integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can…