CVE-2022-44000 to CVE-2022-44999
122 CVEs with public proof-of-concept exploits.
- CVE-2022-440001 PoCAn issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute…
- CVE-2022-440011 PoCAn issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed.
- CVE-2022-440031 PoCAn issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is…
- CVE-2022-440041 PoCAn issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can…
- CVE-2022-440051 PoCAn issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up…
- CVE-2022-440061 PoCAn issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally…
- CVE-2022-440071 PoCAn issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an…
- CVE-2022-440081 PoCAn issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retrieved by accessing…
- CVE-2022-440121 PoCAn issue was discovered in /DS/LM_API/api/SelectionService/InsertQueryWithActiveRelationsReturnId in Simmeth Lieferantenmanager before…
- CVE-2022-440131 PoCAn issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can make various API calls without authentication because…
- CVE-2022-440141 PoCAn issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to fetch arbitrary…
- CVE-2022-440151 PoCAn issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features,…
- CVE-2022-440161 PoCAn issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web server by abusing…
- CVE-2022-440171 PoCAn issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can log back into a…
- CVE-2022-440192 PoCsIn Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.
- CVE-2022-440371 PoCAn access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2…
- CVE-2022-440381 PoCRussound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component.
- CVE-2022-440791 PoCpycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component…
- CVE-2022-440811 PoCLodepng v20220717 was discovered to contain a segmentation fault via the function pngdetail.
- CVE-2022-440961 PoCSanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and…
- CVE-2022-440971 PoCBook Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access…
- CVE-2022-441081 PoCpdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc.
- CVE-2022-441091 PoCpdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*, Object*, int).
- CVE-2022-441181 PoCdedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.
- CVE-2022-441361 PoCZenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
- CVE-2022-441497 PoCsThe web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd…
- CVE-2022-441511 PoCSimple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.
- CVE-2022-441561 PoCTenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind.
- CVE-2022-441581 PoCTenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function via set_device_name.
- CVE-2022-441671 PoCTenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer.
- CVE-2022-442041 PoCD-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.
- CVE-2022-442151 PoCThere is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.
- CVE-2022-442351 PoCBeijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) is vulnerable to Cross Site Scripting (XSS).
- CVE-2022-442491 PoCTOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.
- CVE-2022-442501 PoCTOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.
- CVE-2022-442511 PoCTOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.
- CVE-2022-442521 PoCTOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.
- CVE-2022-442531 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.
- CVE-2022-442541 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.
- CVE-2022-442551 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.
- CVE-2022-442561 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.
- CVE-2022-442571 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.
- CVE-2022-442581 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.
- CVE-2022-442591 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the…
- CVE-2022-442601 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules…
- CVE-2022-442622 PoCsff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
- CVE-2022-442671 PoCImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left…
- CVE-2022-4426834 PoCsImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could…
- CVE-2022-442761 PoCIn Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
- CVE-2022-442791 PoCGarage Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /garage/php_action/createBrand.php.
- CVE-2022-442831 PoCAVS Audio Converter 10.3 is vulnerable to Buffer Overflow.
- CVE-2022-442841 PoCDinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS).
- CVE-2022-442902 PoCswebTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
- CVE-2022-442912 PoCswebTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
- CVE-2022-442981 PoCSiteServer CMS 7.1.3 is vulnerable to SQL Injection.
- CVE-2022-443112 PoCshtml2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo) at procesador.c.…
- CVE-2022-443121 PoCPicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceInteger function in expression.c when called…
- CVE-2022-443181 PoCPicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrcat function in cstdlib/string.c when called from…
- CVE-2022-443211 PoCPicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexSkipComment function in lex.c when called from…
- CVE-2022-443541 PoCSolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
- CVE-2022-443551 PoCSolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php.
- CVE-2022-443562 PoCsWAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which…
- CVE-2022-443621 PoCTenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule.
- CVE-2022-443651 PoCTenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd.
- CVE-2022-443661 PoCTenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo.
- CVE-2022-443671 PoCTenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo.
- CVE-2022-443731 PoCA stack overflow vulnerability exists in TrendNet Wireless AC Easy-Upgrader TEW-820AP (Version v1.0R, firmware version 1.01.B01) which may…
- CVE-2022-443801 PoCSnipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.
- CVE-2022-443811 PoCSnipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.
- CVE-2022-443842 PoCsAn arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2022-444511 PoCA use of uninitialized pointer vulnerability exists in the MSI format atom functionality of Open Babel 3.1.1 and master commit 530dbfa3. A…
- CVE-2022-445691 PoCA locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.
- CVE-2022-445881 PoCWordPress Cryptocurrency Widgets Pack Plugin <=1.8.1 is vulnerable to SQL Injection
- CVE-2022-446382 PoCsIn libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an…
- CVE-2022-446451 PoCApache Linkis (incubating): The DatasourceManager module has a serialization attack vulnerability
- CVE-2022-446661 PoCWindows Contacts Remote Code Execution Vulnerability
- CVE-2022-447021 PoCWindows Terminal Remote Code Execution Vulnerability
- CVE-2022-447241 PoCThe Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject…
- CVE-2022-447261 PoCThe TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.
- CVE-2022-447271 PoCThe EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).
- CVE-2022-447891 PoCA logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code…
- CVE-2022-447922 PoCshandle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used…
- CVE-2022-447932 PoCshandle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be…
- CVE-2022-448301 PoCSourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact…
- CVE-2022-448321 PoCD-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.
- CVE-2022-448431 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the…
- CVE-2022-448441 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the…
- CVE-2022-448491 PoCA Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator…
- CVE-2022-448701 PoCA reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML…
- CVE-2022-448752 PoCsKioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain…
- CVE-2022-4487719 PoCsKEVlogin/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS…
- CVE-2022-448971 PoCA cross-site scripting (XSS) vulnerability in ApolloTheme AP PageBuilder component through 2.4.4 allows attackers to execute arbitrary web…
- CVE-2022-448981 PoCThe MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050,…
- CVE-2022-449001 PoCA directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows…
- CVE-2022-449101 PoCBinbloom 2.0 was discovered to contain a heap buffer overflow via the read_pointer function at /binbloom-master/src/helpers.c.
- CVE-2022-449281 PoCD-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.
- CVE-2022-449291 PoCAn access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP…
- CVE-2022-449301 PoCD-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.
- CVE-2022-449311 PoCTenda A18 v15.13.07.09 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.
- CVE-2022-449321 PoCAn access control issue in Tenda A18 v15.13.07.09 allows unauthenticated attackers to access the Telnet service.
- CVE-2022-449371 PoCBosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module.
- CVE-2022-449381 PoCWeak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.
- CVE-2022-449391 PoCEfs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This…
- CVE-2022-449421 PoCCasdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.
- CVE-2022-449442 PoCsRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at…
- CVE-2022-449451 PoCRukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.
- CVE-2022-449462 PoCsRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at…
- CVE-2022-449472 PoCsRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at…
- CVE-2022-449482 PoCsRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature…
- CVE-2022-449492 PoCsRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at…
- CVE-2022-449502 PoCsRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at…
- CVE-2022-449512 PoCsRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at…
- CVE-2022-449522 PoCsRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in…
- CVE-2022-449531 PoCwebtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This…
- CVE-2022-449541 PoCwebtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php. This…
- CVE-2022-449551 PoCwebtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allows…
- CVE-2022-449561 PoCwebtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This…
- CVE-2022-449572 PoCswebtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This…
- CVE-2022-449591 PoCwebtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /meetings/listmeetings.php. This…
- CVE-2022-449601 PoCwebtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component…
- CVE-2022-449611 PoCwebtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This…
- CVE-2022-449621 PoCwebtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php. This…