CVE-2022-45000 to CVE-2022-45999
201 CVEs with public proof-of-concept exploits.
- CVE-2022-450031 PoCGophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.
- CVE-2022-450041 PoCGophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page.
- CVE-2022-450252 PoCsMarkdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF…
- CVE-2022-450261 PoCAn issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM…
- CVE-2022-450271 PoCperfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address.
- CVE-2022-450281 PoCA cross-site scripting (XSS) vulnerability in Arris NVG443B 9.3.0h3d36 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2022-450302 PoCsA SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with…
- CVE-2022-450331 PoCA cross-site scripting (XSS) vulnerability in Expense Tracker 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2022-450371 PoCA cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts…
- CVE-2022-450381 PoCA cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web…
- CVE-2022-450431 PoCTenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.
- CVE-2022-450451 PoCMultiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL…
- CVE-2022-450471 PoCApache MINA SSHD: Java unsafe deserialization vulnerability
- CVE-2022-450591 PoCAn issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish…
- CVE-2022-450631 PoCxterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command…
- CVE-2022-451151 PoCA buffer overflow vulnerability exists in the Attribute Arena functionality of Ichitaro 2022 1.0.1.57600. A specially crafted document can…
- CVE-2022-451241 PoCAn information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A…
- CVE-2022-451291 PoCPayara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability…
- CVE-2022-451301 PoCPlesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific…
- CVE-2022-451321 PoCIn Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2…
- CVE-2022-451441 PoCAlgoo Tracim before 4.4.2 allows XSS via HTML file upload.
- CVE-2022-451541 PoCsupportconfig does not remove passwords in /etc/iscsi/iscsid.conf and /etc/target/lio_setup.sh
- CVE-2022-451632 PoCsAn information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010,…
- CVE-2022-451681 PoCAn issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the…
- CVE-2022-451701 PoCAn issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the…
- CVE-2022-451711 PoCAn issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur…
- CVE-2022-451721 PoCAn issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the…
- CVE-2022-451731 PoCAn issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the…
- CVE-2022-451741 PoCAn issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under…
- CVE-2022-451751 PoCAn issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the…
- CVE-2022-451761 PoCAn issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the…
- CVE-2022-451781 PoCAn issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the…
- CVE-2022-451801 PoCAn issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export…
- CVE-2022-452021 PoCGPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at…
- CVE-2022-452041 PoCGPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a memory leak via the function dimC_box_read at isomedia/box_code_3gpp.c.
- CVE-2022-452051 PoCJeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
- CVE-2022-452071 PoCJeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
- CVE-2022-452081 PoCJeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
- CVE-2022-452101 PoCJeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
- CVE-2022-452131 PoCperfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.
- CVE-2022-452171 PoCA cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or…
- CVE-2022-452691 PoCA directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read…
- CVE-2022-452831 PoCGPAC MP4box v2.0.0 was discovered to contain a stack overflow in the smil_parse_time_list parameter at /scenegraph/svg_attributes.c.
- CVE-2022-452901 PoCKbase Doc v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /web/IndexController.java.
- CVE-2022-452972 PoCsEQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.
- CVE-2022-452991 PoCAn issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL.
- CVE-2022-453131 PoCMikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows…
- CVE-2022-453151 PoCMikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows…
- CVE-2022-453321 PoCLibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.
- CVE-2022-453371 PoCTenda TX9 Pro v22.03.02.10 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.
- CVE-2022-453431 PoCGPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at…
- CVE-2022-453542 PoCsWordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
- CVE-2022-453621 PoCWordPress Paytm Payment Gateway Plugin <= 2.7.0 is vulnerable to Server Side Request Forgery (SSRF)
- CVE-2022-453651 PoCWordPress Stock Ticker Plugin <= 3.23.2 is vulnerable to Cross Site Scripting (XSS)
- CVE-2022-454361 PoCStored cross-site scripting vulnerability in network maps editor feature
- CVE-2022-454511 PoCLocal privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber…
- CVE-2022-454602 PoCsMultiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL…
- CVE-2022-454721 PoCCAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.
- CVE-2022-454971 PoCTenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at…
- CVE-2022-454981 PoCAn issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to…
- CVE-2022-454991 PoCTenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.
- CVE-2022-455011 PoCTenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/wifiSSIDset.
- CVE-2022-455031 PoCTenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the linkEn parameter at /goform/setAutoPing.
- CVE-2022-455041 PoCAn issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers…
- CVE-2022-455051 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.
- CVE-2022-455061 PoCTenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.
- CVE-2022-455071 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.
- CVE-2022-455081 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.
- CVE-2022-455091 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName.
- CVE-2022-455101 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset.
- CVE-2022-455111 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.
- CVE-2022-455121 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter.
- CVE-2022-455131 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/P2pListFilter.
- CVE-2022-455141 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/webExcptypemanFilter.
- CVE-2022-455151 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the entries parameter at /goform/addressNat.
- CVE-2022-455161 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/NatStaticSetting.
- CVE-2022-455171 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer.
- CVE-2022-455181 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SetIpBind.
- CVE-2022-455191 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter.
- CVE-2022-455201 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.
- CVE-2022-455211 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter.
- CVE-2022-455221 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter.
- CVE-2022-455231 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.
- CVE-2022-455241 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave.
- CVE-2022-455251 PoCTenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo.
- CVE-2022-455261 PoCSQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via…
- CVE-2022-455271 PoCFile upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload…
- CVE-2022-455371 PoCEyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL".
- CVE-2022-455381 PoCEyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL".
- CVE-2022-455391 PoCEyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new file.
- CVE-2022-455401 PoCEyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed…
- CVE-2022-455411 PoCEyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a…
- CVE-2022-455421 PoCEyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file.
- CVE-2022-455441 PoCInsecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary…
- CVE-2022-455461 PoCInformation Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacker to obtain…
- CVE-2022-455521 PoCAn Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive…
- CVE-2022-455531 PoCAn issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via…
- CVE-2022-455571 PoCCross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via file names.
- CVE-2022-455581 PoCCross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via the meta tag.
- CVE-2022-455621 PoCInsecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with…
- CVE-2022-455861 PoCStack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.
- CVE-2022-455871 PoCStack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service.
- CVE-2022-455991 PoCAztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to…
- CVE-2022-456001 PoCAztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass…
- CVE-2022-456131 PoCBook Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This…
- CVE-2022-456341 PoCAn issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows authenticated attacker to gain access to sensitive…
- CVE-2022-456351 PoCAn issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account…
- CVE-2022-456362 PoCsAn issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization…
- CVE-2022-456372 PoCsAn insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry…
- CVE-2022-456392 PoCsOS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the…
- CVE-2022-456402 PoCsTenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).
- CVE-2022-456411 PoCTenda AC6V1.0 V15.03.05.19 is vulnerable to Buffer Overflow via formSetMacFilterCfg.
- CVE-2022-456431 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceId parameter in the addWifiMacFilter function.
- CVE-2022-456441 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceId parameter in the formSetClientState function.
- CVE-2022-456451 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceMac parameter in the addWifiMacFilter function.
- CVE-2022-456461 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeedUp parameter in the formSetClientState function.
- CVE-2022-456471 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeed parameter in the formSetClientState function.
- CVE-2022-456481 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the devName parameter in the formSetDeviceName function.
- CVE-2022-456491 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the endIp parameter in the formSetPPTPServer function.
- CVE-2022-456501 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the firewallEn parameter in the formSetFirewallCfg function.
- CVE-2022-456511 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the list parameter in the formSetVirtualSer function.
- CVE-2022-456521 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function.
- CVE-2022-456531 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the page parameter in the fromNatStaticSetting function.
- CVE-2022-456541 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the ssid parameter in the form_fast_setting_wifi_set function.
- CVE-2022-456551 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the timeZone parameter in the form_fast_setting_wifi_set…
- CVE-2022-456561 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.
- CVE-2022-456571 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.
- CVE-2022-456581 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the schedEndTime parameter in the setSchedWifi function.
- CVE-2022-456591 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat…
- CVE-2022-456601 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the schedStartTime parameter in the setSchedWifi function.
- CVE-2022-456611 PoCTenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function.
- CVE-2022-456631 PoCTenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.
- CVE-2022-456641 PoCTenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDget function.
- CVE-2022-456651 PoCTenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.
- CVE-2022-456661 PoCTenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.
- CVE-2022-456671 PoCTenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
- CVE-2022-456681 PoCTenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
- CVE-2022-456691 PoCTenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterGet function.
- CVE-2022-456701 PoCTenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.
- CVE-2022-456711 PoCTenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formSetAppFilterRule function.
- CVE-2022-456721 PoCTenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the formWx3AuthorizeSet function.
- CVE-2022-456731 PoCTenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
- CVE-2022-456741 PoCTenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
- CVE-2022-456771 PoCSQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php.
- CVE-2022-456851 PoCA stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
- CVE-2022-456882 PoCsA stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted…
- CVE-2022-456901 PoCA stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a…
- CVE-2022-456931 PoCJettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a…
- CVE-2022-456991 PoCCommand injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute…
- CVE-2022-457015 PoCsArris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
- CVE-2022-457031 PoCHeap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.
- CVE-2022-457111 PoCIP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the…
- CVE-2022-457281 PoCDoctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
- CVE-2022-457291 PoCA cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web…
- CVE-2022-457481 PoCAn issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromChannel in file…
- CVE-2022-457682 PoCsCommand Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute…
- CVE-2022-457691 PoCA cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2022-457701 PoCImproper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalation.
- CVE-2022-457713 PoCsAn issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a…
- CVE-2022-457821 PoCAn issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation…
- CVE-2022-458051 PoCWordPress Paytm Payment Gateway Plugin <= 2.7.3 is vulnerable to SQL Injection
- CVE-2022-458082 PoCsWordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
- CVE-2022-458351 PoCWordPress PhonePe Payment Solutions Plugin <= 1.0.15 is vulnerable to Server Side Request Forgery (SSRF)
- CVE-2022-458361 PoCWordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS)
- CVE-2022-458661 PoCqpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory…
- CVE-2022-458681 PoCThe web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which…
- CVE-2022-458691 PoCA race condition in the x86 KVM subsystem in the Linux kernel through 6.1-rc6 allows guest OS users to cause a denial of service (host OS…
- CVE-2022-458721 PoCiTerm2 before 3.4.18 mishandles a DECRQSS response.
- CVE-2022-458891 PoCPlanet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the…
- CVE-2022-458901 PoCIn Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g.,…
- CVE-2022-458911 PoCPlanet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or…
- CVE-2022-458921 PoCIn Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function,…
- CVE-2022-458931 PoCPlanet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by…
- CVE-2022-458941 PoCGetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.
- CVE-2022-458951 PoCPlanet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx…
- CVE-2022-458991 PoCNokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell…
- CVE-2022-459142 PoCsThe ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-2130-V4.3 20190629…
- CVE-2022-459153 PoCsILIAS before 7.16 allows OS Command Injection.
- CVE-2022-459163 PoCsILIAS before 7.16 allows XSS.
- CVE-2022-459174 PoCsILIAS before 7.16 has an Open Redirect.
- CVE-2022-459182 PoCsILIAS before 7.16 allows External Control of File Name or Path.
- CVE-2022-459223 PoCsAn issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid…
- CVE-2022-459233 PoCsAn issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows…
- CVE-2022-459243 PoCsAn issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate2 allows a…
- CVE-2022-459253 PoCsAn issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext.…
- CVE-2022-459263 PoCsAn issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a…
- CVE-2022-459273 PoCsAn issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the…
- CVE-2022-459283 PoCsA remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user…
- CVE-2022-459332 PoCsKubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require…
- CVE-2022-459343 PoCsAn issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via…
- CVE-2022-459422 PoCsA Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.
- CVE-2022-459561 PoCBoa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone…
- CVE-2022-459571 PoCZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.
- CVE-2022-459621 PoCOpen Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.
- CVE-2022-459771 PoCTenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.
- CVE-2022-459791 PoCTenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set .
- CVE-2022-459801 PoCTenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .
- CVE-2022-459881 PoCstarsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted file upload.
- CVE-2022-459951 PoCThere is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the web service not…
- CVE-2022-459961 PoCTenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.
- CVE-2022-459971 PoCTenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.