CVE-2022-41000 to CVE-2022-41999
139 CVEs with public proof-of-concept exploits.
- CVE-2022-410001 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410011 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410021 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410031 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410041 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410051 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410061 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410071 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410081 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410091 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410101 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410111 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410121 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410131 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410141 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410151 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410161 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410171 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410181 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410191 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410201 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410211 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410221 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410231 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410241 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410251 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410261 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410271 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410281 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410291 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410301 PoCSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD…
- CVE-2022-410321 PoCNuGet Client Elevation of Privilege Vulnerability
- CVE-2022-410342 PoCsVisual Studio Code Remote Code Execution Vulnerability
- CVE-2022-4104014 PoCsKEVMicrosoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2022-410762 PoCsPowerShell Remote Code Execution Vulnerability
- CVE-2022-410802 PoCsKEVMicrosoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2022-4108212 PoCsKEVMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2022-410991 PoCBitLocker Security Feature Bypass Vulnerability
- CVE-2022-411141 PoCWindows Bind Filter Driver Elevation of Privilege Vulnerability
- CVE-2022-411381 PoCIn Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
- CVE-2022-411391 PoCMITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary…
- CVE-2022-411541 PoCA directory traversal vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A…
- CVE-2022-412183 PoCsIn drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting…
- CVE-2022-412201 PoCmd2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's…
- CVE-2022-412211 PoCThe client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center…
- CVE-2022-412721 PoCAn unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP…
- CVE-2022-413111 PoCA stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch…
- CVE-2022-413121 PoCA stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch…
- CVE-2022-413131 PoCA stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch…
- CVE-2022-413221 PoCIn Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user…
- CVE-2022-413332 PoCsAn uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login…
- CVE-2022-413432 PoCsregisterFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font…
- CVE-2022-413471 PoCAn issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to…
- CVE-2022-413528 PoCsKEVAn issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio…
- CVE-2022-413584 PoCsA stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or…
- CVE-2022-413761 PoCMetro UI v4.4.0 to v4.5.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function.
- CVE-2022-413922 PoCsA cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2022-413951 PoCTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter…
- CVE-2022-413961 PoCTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function…
- CVE-2022-414011 PoCOpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system,…
- CVE-2022-414031 PoCOpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at…
- CVE-2022-414042 PoCsAn issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service…
- CVE-2022-414121 PoCAn issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side…
- CVE-2022-414131 PoCperfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted…
- CVE-2022-414151 PoCAcer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows…
- CVE-2022-414191 PoCBento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.
- CVE-2022-414231 PoCBento4 v1.6.0-639 was discovered to contain a segmentation violation in the mp4fragment component.
- CVE-2022-414241 PoCBento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls.
- CVE-2022-414251 PoCBento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4decrypt.
- CVE-2022-414261 PoCBento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4split.
- CVE-2022-414271 PoCBento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux.
- CVE-2022-414281 PoCBento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.
- CVE-2022-414291 PoCBento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag.
- CVE-2022-414301 PoCBento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.
- CVE-2022-414311 PoCxzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. This vulnerability…
- CVE-2022-414413 PoCsMultiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a…
- CVE-2022-414451 PoCA cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute arbitrary web…
- CVE-2022-414461 PoCAn access control issue in /Admin/dashboard.php of Record Management System using CodeIgniter v1.0 allows attackers to access and modify…
- CVE-2022-414732 PoCsRPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.
- CVE-2022-414741 PoCRPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily change the password of…
- CVE-2022-414751 PoCRPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator…
- CVE-2022-414771 PoCA security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows…
- CVE-2022-414951 PoCClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.
- CVE-2022-414961 PoCiCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
- CVE-2022-414971 PoCClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.
- CVE-2022-415181 PoCTOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at…
- CVE-2022-415221 PoCTOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.
- CVE-2022-415251 PoCTOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at…
- CVE-2022-415401 PoCThe web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are…
- CVE-2022-415411 PoCTP-Link AX10v1 V1_211117 allows attackers to execute a replay attack by using a previously transmitted encrypted authentication message…
- CVE-2022-415447 PoCsGetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in…
- CVE-2022-415471 PoCMobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the…
- CVE-2022-416222 PoCsiControl SOAP vulnerability
- CVE-2022-416391 PoCA heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and…
- CVE-2022-416491 PoCA heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0. A…
- CVE-2022-416541 PoCAn authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A…
- CVE-2022-416745 PoCsAn issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the…
- CVE-2022-416785 PoCsApache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCE
- CVE-2022-416841 PoCA heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file directory part of a…
- CVE-2022-416972 PoCsA user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can…
- CVE-2022-417171 PoCExcessive memory growth in net/http and golang.org/x/net/http2
- CVE-2022-417231 PoCDenial of service via crafted HTTP/2 stream in net/http and golang.org/x/net
- CVE-2022-417411 PoCNGINX ngx_http_mp4_module vulnerability CVE-2022-41741
- CVE-2022-417421 PoCNGINX ngx_http_mp4_module vulnerability CVE-2022-41742
- CVE-2022-417601 PoCAn issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager…
- CVE-2022-417611 PoCAn issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM…
- CVE-2022-417621 PoCAn issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any…
- CVE-2022-417631 PoCAn issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user,…
- CVE-2022-417931 PoCAn out-of-bounds write vulnerability exists in the CSR format title functionality of Open Babel 3.1.1 and master commit 530dbfa3. A…
- CVE-2022-417941 PoCA heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted…
- CVE-2022-418003 PoCsAppliance mode iControl REST vulnerability
- CVE-2022-418281 PoCIn Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check…
- CVE-2022-418371 PoCAn out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO…
- CVE-2022-418381 PoCA code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A…
- CVE-2022-418403 PoCsWordPress Welcart eCommerce plugin <= 2.7.7 - Unauth. Directory Traversal vulnerability
- CVE-2022-418411 PoCAn issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/Ap4File.cpp, which…
- CVE-2022-418421 PoCAn issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.
- CVE-2022-418431 PoCAn issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than…
- CVE-2022-418441 PoCAn issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a different vulnerability…
- CVE-2022-418451 PoCAn issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function…
- CVE-2022-418461 PoCAn issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::ReallocateBuffer in…
- CVE-2022-418471 PoCAn issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*,…
- CVE-2022-418531 PoCRemote code execution in HyperSQL DataBase
- CVE-2022-418761 PoCezplatform-graphql GraphQL queries can expose password hashes
- CVE-2022-418841 PoCSeg fault in `ndarray_tensor_bridge` due to zero and large inputs in Tensorflow
- CVE-2022-419231 PoCGrails Spring Security Core plugin vulnerable to privilege escalation
- CVE-2022-419241 PoCTailscale Windows daemon is vulnerable to RCE via CSRF
- CVE-2022-419581 PoCDeserialization Vulnerability by yaml config input in super-xray
- CVE-2022-419661 PoCXStream Denial of Service via stack overflow
- CVE-2022-419732 PoCsmultipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with…
- CVE-2022-419742 PoCsmultipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with…
- CVE-2022-419761 PoCAn privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the…
- CVE-2022-419771 PoCAn out of bounds read vulnerability exists in the way OpenImageIO version v2.3.19.0 processes string fields in TIFF image files. A…
- CVE-2022-419811 PoCA stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0. A specially-crafted targa file…
- CVE-2022-419851 PoCAn authentication bypass vulnerability exists in the Authentication functionality of Weston Embedded uC-FTPs v 1.98.00. A specially…
- CVE-2022-419881 PoCAn information disclosure vulnerability exists in the OpenImageIO::decode_iptc_iim() functionality of OpenImageIO Project OpenImageIO…
- CVE-2022-419911 PoCA heap-based buffer overflow vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020.…
- CVE-2022-419921 PoCA memory corruption vulnerability exists in the VHD File Format parsing CXSPARSE record functionality of PowerISO PowerISO 8.3. A…
- CVE-2022-419991 PoCA denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and…