CVE-2022-46000 to CVE-2022-46999
119 CVEs with public proof-of-concept exploits.
- CVE-2022-460201 PoCWBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
- CVE-2022-460713 PoCsThere is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.
- CVE-2022-460722 PoCsHelmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.
- CVE-2022-460733 PoCsHelmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS).
- CVE-2022-460742 PoCsHelmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to…
- CVE-2022-460761 PoCD-Link DIR-869 DIR869Ax_FW102B15 is vulnerable to Authentication Bypass via phpcgi.
- CVE-2022-460803 PoCsNexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.
- CVE-2022-460872 PoCsCloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through…
- CVE-2022-460881 PoCOnline Flight Booking Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the feedback form.
- CVE-2022-460891 PoCCross Site Scripting (XSS) vulnerability in the add-airline form of Online Flight Booking Management System v1.0 allows attackers to…
- CVE-2022-460911 PoCCross Site Scripting (XSS) vulnerability in the feedback form of Online Flight Booking Management System v1.0 allows attackers to execute…
- CVE-2022-460931 PoCHospital Management System v1.0 is vulnerable to SQL Injection. Attackers can gain administrator privileges without the need for a password.
- CVE-2022-460951 PoCSourcecodester Covid-19 Directory on Vaccination System 1.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via…
- CVE-2022-460961 PoCA Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid-19 Directory on Vaccination System v1.0 allows attackers to…
- CVE-2022-461091 PoCTenda AC15 V15.03.06.23 is vulnerable to Buffer Overflow via function formSetClientState.
- CVE-2022-461351 PoCIn AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload…
- CVE-2022-461611 PoCCode injection in pdfmake
- CVE-2022-461641 PoCAccount takeover via prototype vulnerability
- CVE-2022-461661 PoCSpring Boot Admins integrated notifier support allows arbitrary code execution
- CVE-2022-4616952 PoCsKEVUnauthenticated Command Injection
- CVE-2022-461711 PoCTauri vulnerable to path traversal
- CVE-2022-461721 PoCauthentik allows existing authenticated users to create arbitrary accounts
- CVE-2022-461751 PoCJSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The…
- CVE-2022-461791 PoCLiuOS vulnerable to Authorization Bypass through User-Controlled Key
- CVE-2022-462801 PoCA use of uninitialized pointer vulnerability exists in the PQS format pFormat functionality of Open Babel 3.1.1 and master commit…
- CVE-2022-462891 PoCMultiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3.…
- CVE-2022-462901 PoCMultiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3.…
- CVE-2022-462911 PoCMultiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open…
- CVE-2022-462921 PoCMultiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open…
- CVE-2022-462931 PoCMultiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open…
- CVE-2022-462941 PoCMultiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open…
- CVE-2022-462951 PoCMultiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open…
- CVE-2022-463321 PoCProofpoint Enterprise Protection (PPS/PoD) XSS in "Attachment Names"
- CVE-2022-463331 PoCProofpoint Enterprise Protection perl eval() arbitrary command execution
- CVE-2022-463341 PoCProofpoint Enterprise Protection Local Privilege Escalation
- CVE-2022-463646 PoCsApache CXF SSRF Vulnerability
- CVE-2022-463771 PoCAn out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A…
- CVE-2022-463781 PoCAn out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A…
- CVE-2022-463813 PoCsCertain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_template_v0.php…
- CVE-2022-463871 PoCConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to…
- CVE-2022-463954 PoCsAn issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain…
- CVE-2022-464402 PoCsttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.
- CVE-2022-464432 PoCsmesinkasir Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter.
- CVE-2022-464634 PoCsAn access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without…
- CVE-2022-464751 PoCD-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function.
- CVE-2022-464761 PoCD-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.
- CVE-2022-464781 PoCThe RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute…
- CVE-2022-464842 PoCsInformation disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows…
- CVE-2022-464852 PoCsData Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text…
- CVE-2022-464861 PoCA lack of pointer-validation logic in the __scone_dispatch component of SCONE before v5.8.0 for Intel SGX allows attackers to access…
- CVE-2022-464891 PoCGPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the gf_isom_box_parse_ex function at box_funcs.c.
- CVE-2022-464901 PoCGPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the afrt_box_read function at box_code_adobe.c.
- CVE-2022-464911 PoCA Cross-Site Request Forgery (CSRF) vulnerability in the Add Administrator function of the default version of nbnbk allows attackers to…
- CVE-2022-464971 PoCHospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at…
- CVE-2022-464981 PoCHospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at…
- CVE-2022-464991 PoCHospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at…
- CVE-2022-465051 PoCAn issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an…
- CVE-2022-465301 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mac parameter at /goform/GetParentControlInfo.
- CVE-2022-465311 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/addWifiMacFilter.
- CVE-2022-465321 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceMac parameter at /goform/addWifiMacFilter.
- CVE-2022-465331 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the limitSpeed parameter at /goform/SetClientState.
- CVE-2022-465341 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the speed_dir parameter at /goform/SetSpeedWan.
- CVE-2022-465351 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/SetClientState.
- CVE-2022-465361 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the limitSpeedUp parameter at /goform/SetClientState.
- CVE-2022-465371 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the security parameter at /goform/WifiBasicSet.
- CVE-2022-465381 PoCTenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.
- CVE-2022-465391 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the security_5g parameter at /goform/WifiBasicSet.
- CVE-2022-465401 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the entrys parameter at /goform/addressNat.
- CVE-2022-465411 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the ssid parameter at /goform/fast_setting_wifi_set.
- CVE-2022-465421 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/addressNat.
- CVE-2022-465431 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mitInterface parameter at /goform/addressNat.
- CVE-2022-465441 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the cmdinput parameter at /goform/exeCommand.
- CVE-2022-465451 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.
- CVE-2022-465461 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the entrys parameter at /goform/RouteStatic.
- CVE-2022-465471 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/VirtualSer.
- CVE-2022-465481 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/DhcpListClient.
- CVE-2022-465491 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/saveParentControlInfo.
- CVE-2022-465501 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the urls parameter at /goform/saveParentControlInfo.
- CVE-2022-465511 PoCTenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the time parameter at /goform/saveParentControlInfo.
- CVE-2022-465523 PoCsD-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the…
- CVE-2022-465801 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function.
- CVE-2022-465811 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup…
- CVE-2022-465821 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the login_name parameter in the do_graph_auth (sub_4061E0)…
- CVE-2022-465831 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.
- CVE-2022-465841 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the…
- CVE-2022-465851 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the REMOTE_USER parameter in the get_access (sub_45AC2C) function.
- CVE-2022-465861 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the…
- CVE-2022-465891 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_option parameter in the tools_netstat…
- CVE-2022-465901 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_rsname parameter in the tools_netstat…
- CVE-2022-465911 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reject_url parameter in the reject (sub_41BD60) function.
- CVE-2022-465941 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the update_file_name parameter in the auto_up_fw (sub_420A04)…
- CVE-2022-465961 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the del_num parameter in the icp_delete_img (sub_41DEDC) function.
- CVE-2022-465971 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the…
- CVE-2022-465991 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4)…
- CVE-2022-466001 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the action…
- CVE-2022-466011 PoCTRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setbg_num parameter in the icp_setbg_img (sub_41DD68) function.
- CVE-2022-466031 PoCAn issue in Inkdrop v5.4.1 allows attackers to execute arbitrary commands via uploading a crafted markdown file.
- CVE-2022-466043 PoCsAn issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a…
- CVE-2022-466221 PoCA cross-site scripting (XSS) vulnerability in Judging Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via…
- CVE-2022-466231 PoCJudging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.
- CVE-2022-466311 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the…
- CVE-2022-466341 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the…
- CVE-2022-466401 PoCNanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP…
- CVE-2022-466411 PoCD-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the…
- CVE-2022-466421 PoCD-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the…
- CVE-2022-466491 PoCAcemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary…
- CVE-2022-466898 PoCsA race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1,…
- CVE-2022-467181 PoCA logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, macOS Big…
- CVE-2022-467221 PoCA logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of…
- CVE-2022-467411 PoCOut-of-bounds read in gather_tree in PaddlePaddle before 2.4.
- CVE-2022-467703 PoCsqubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU…
- CVE-2022-468361 PoCPHP code injection in watolib
- CVE-2022-468881 PoCMultiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrary web…
- CVE-2022-469071 PoCApache JSPWiki: XSS Injection points in several plugins
- CVE-2022-469342 PoCskkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at…
- CVE-2022-469451 PoCNagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.
- CVE-2022-469651 PoCPrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.
- CVE-2022-469661 PoCRevenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.
- CVE-2022-469681 PoCA stored cross-site scripting (XSS) vulnerability in /index.php?page=help of Revenue Collection System v1.0 allows attackers to execute…