CVE-2022-42000 to CVE-2022-42999
91 CVEs with public proof-of-concept exploits.
- CVE-2022-420451 PoCCertain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zemana AntiMalware…
- CVE-2022-420461 PoCwfshbr64.sys and wfshbr32.sys specially crafted IOCTL allows arbitrary user to perform local privilege escalation
- CVE-2022-420531 PoCTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer…
- CVE-2022-420541 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow…
- CVE-2022-420551 PoCMultiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and…
- CVE-2022-420581 PoCTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This…
- CVE-2022-420601 PoCTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This…
- CVE-2022-420641 PoCOnline Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.
- CVE-2022-420661 PoCOnline Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.
- CVE-2022-420671 PoCOnline Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerability
- CVE-2022-420691 PoCOnline Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.
- CVE-2022-420701 PoCOnline Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).
- CVE-2022-420711 PoCOnline Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.
- CVE-2022-420771 PoCTenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
- CVE-2022-420781 PoCTenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
- CVE-2022-420791 PoCTenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWifiBasicSet.
- CVE-2022-420801 PoCTenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a heap overflow via sched_start_time parameter.
- CVE-2022-420811 PoCTenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via sched_end_time parameter.
- CVE-2022-420861 PoCTenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.
- CVE-2022-420871 PoCTenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
- CVE-2022-420922 PoCsBackdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third…
- CVE-2022-420943 PoCsBackdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.
- CVE-2022-420953 PoCsBackdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
- CVE-2022-420963 PoCsBackdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
- CVE-2022-420972 PoCsBackdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .
- CVE-2022-420982 PoCsKLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.
- CVE-2022-420991 PoCKLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subject input.
- CVE-2022-421001 PoCKLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location input reply-form.
- CVE-2022-421181 PoCA Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before…
- CVE-2022-421391 PoCDelta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.
- CVE-2022-421401 PoCDelta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.
- CVE-2022-421411 PoCDelta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.
- CVE-2022-421491 PoCkkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
- CVE-2022-421501 PoCTinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause…
- CVE-2022-421561 PoCD-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at…
- CVE-2022-421591 PoCD-Link COVR 1200,1202,1203 v1.08 was discovered to have a predictable seed in a Pseudo-Random Number Generator.
- CVE-2022-421601 PoCD-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at…
- CVE-2022-421611 PoCD-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the /SetTriggerWPS/PIN parameter at…
- CVE-2022-421631 PoCTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromNatStaticSetting.
- CVE-2022-421641 PoCTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetClientState.
- CVE-2022-421651 PoCTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.
- CVE-2022-421661 PoCTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetSpeedWan.
- CVE-2022-421671 PoCTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.
- CVE-2022-421681 PoCTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromSetIpMacBind.
- CVE-2022-421691 PoCTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/addWifiMacFilter.
- CVE-2022-421701 PoCTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formWifiWpsStart.
- CVE-2022-421711 PoCTenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo.
- CVE-2022-421762 PoCsIn PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access.
- CVE-2022-421992 PoCsSimple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.
- CVE-2022-422211 PoCNetgear R6220 v1.1.0.114_1.0.1 suffers from Incorrect Access Control, resulting in a command injection vulnerability.
- CVE-2022-422331 PoCTenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
- CVE-2022-422351 PoCA Stored XSS issue in Student Clearance System v.1.0 allows the injection of arbitrary JavaScript in the Student registration form.
- CVE-2022-422361 PoCA Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form.
- CVE-2022-422371 PoCA SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.
- CVE-2022-422381 PoCA Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.
- CVE-2022-422461 PoCDoufox 0.0.4 contains a CSRF vulnerability that can add system administrator account.
- CVE-2022-422482 PoCsQlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.
- CVE-2022-424571 PoCGenerex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in…
- CVE-2022-4247514 PoCsKEVA heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10,…
- CVE-2022-424841 PoCAn OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP…
- CVE-2022-427033 PoCsmm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse.
- CVE-2022-427101 PoCNice (formerly Nortek) Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e devices are…
- CVE-2022-427192 PoCsA use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be…
- CVE-2022-427205 PoCsVarious refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be…
- CVE-2022-427211 PoCA list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local…
- CVE-2022-427222 PoCsIn the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a…
- CVE-2022-427461 PoCCandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users.…
- CVE-2022-427471 PoCCandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This…
- CVE-2022-427481 PoCCandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users.…
- CVE-2022-427491 PoCCandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is…
- CVE-2022-427891 PoCAn issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13,…
- CVE-2022-428053 PoCsAn integer overflow was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An…
- CVE-2022-428451 PoCThe issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS…
- CVE-2022-428641 PoCA race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1,…
- CVE-2022-428851 PoCA use of uninitialized pointer vulnerability exists in the GRO format res functionality of Open Babel 3.1.1 and master commit 530dbfa3. A…
- CVE-2022-4288955 PoCsApache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
- CVE-2022-428962 PoCsInfo Leak in l2cap_core in the Linux Kernel
- CVE-2022-428991 PoCBentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read and stack overflow issues when opening…
- CVE-2022-429051 PoCIn wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network…
- CVE-2022-429533 PoCsCertain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the…
- CVE-2022-429641 PoCExponential ReDoS in pymatgen leads to denial of service
- CVE-2022-429651 PoCExponential ReDoS in snowflake-connector-python leads to denial of service
- CVE-2022-429661 PoCExponential ReDoS in cleo leads to denial of service
- CVE-2022-429671 PoCXSS in Caret markdown editor leads to remote code execution when viewing crafted Markdown files
- CVE-2022-429691 PoCThe py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a…
- CVE-2022-429801 PoCgo-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.
- CVE-2022-429911 PoCA stored cross-site scripting (XSS) vulnerability in Simple Online Public Access Catalog v1.0 allows attackers to execute arbitrary web…
- CVE-2022-429921 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitrary web scripts or…
- CVE-2022-429931 PoCPassword Storage Application v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Setup page.
- CVE-2022-429981 PoCD-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd.
- CVE-2022-429991 PoCD-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at…