CVE-2022-47000 to CVE-2022-47999
95 CVEs with public proof-of-concept exploits.
- CVE-2022-470021 PoCA vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted…
- CVE-2022-470031 PoCA vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web…
- CVE-2022-470271 PoCTimmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a…
- CVE-2022-470281 PoCAn issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to…
- CVE-2022-470291 PoCAn issue was found in Action Launcher v50.5 allows an attacker to escalate privilege via modification of the intent string to function…
- CVE-2022-470371 PoCSiklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.
- CVE-2022-470401 PoCAn issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running the tcpdump…
- CVE-2022-470421 PoCMCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do.
- CVE-2022-470521 PoCThe web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can be leveraged to…
- CVE-2022-470651 PoCTrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow via the…
- CVE-2022-470691 PoCp7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at…
- CVE-2022-470701 PoCNVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the server twice. In the…
- CVE-2022-470721 PoCSQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter…
- CVE-2022-470753 PoCsAn issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name…
- CVE-2022-470762 PoCsAn issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via…
- CVE-2022-470831 PoCA PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute…
- CVE-2022-470861 PoCGPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_manager/swf_parse.c
- CVE-2022-470871 PoCGPAC MP4box 2.1-DEV-rev574-g9d5bb184b has a Buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c
- CVE-2022-470881 PoCGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow.
- CVE-2022-470891 PoCGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow via gf_vvc_read_sps_bs_internal function of media_tools/av_parsers.c
- CVE-2022-470911 PoCGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.c
- CVE-2022-470921 PoCGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is contains an Integer overflow vulnerability in gf_hevc_read_sps_bs_internal function of…
- CVE-2022-470931 PoCGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to heap use-after-free via filters/dmx_m2ts.c:470 in m2tsdmx_declare_pid
- CVE-2022-470941 PoCGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Null pointer dereference via filters/dmx_m2ts.c:343 in m2tsdmx_declare_pid
- CVE-2022-470951 PoCGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer overflow in hevc_parse_vps_extension function of media_tools/av_parsers.c
- CVE-2022-471021 PoCA cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute arbitrary web…
- CVE-2022-471151 PoCTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepauth parameter at /goform/WifiBasicSet.
- CVE-2022-471161 PoCTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the SYSPS parameter at /goform/SysToolChangePwd.
- CVE-2022-471171 PoCTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security parameter at /goform/WifiBasicSet.
- CVE-2022-471181 PoCTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet.
- CVE-2022-471191 PoCTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the ssid parameter at /goform/WifiBasicSet.
- CVE-2022-471201 PoCTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.
- CVE-2022-471211 PoCTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.
- CVE-2022-471231 PoCTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet.
- CVE-2022-471241 PoCTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet.
- CVE-2022-471281 PoCTenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey2 parameter at /goform/WifiBasicSet.
- CVE-2022-471301 PoCA Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with…
- CVE-2022-471311 PoCA Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.
- CVE-2022-471321 PoCA Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.
- CVE-2022-471941 PoCAn insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of…
- CVE-2022-471951 PoCAn insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of…
- CVE-2022-471961 PoCAn insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of…
- CVE-2022-471971 PoCAn insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of…
- CVE-2022-473731 PoCReflected Cross Site Scripting in Search Functionality of Module Library
- CVE-2022-474471 PoCWordPress WP-Advanced-Search Plugin <= 3.3.8 is vulnerable to Cross Site Request Forgery (CSRF)
- CVE-2022-475011 PoCApache OFBiz: Arbitrary file reading vulnerability
- CVE-2022-475141 PoCAn XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side…
- CVE-2022-475221 PoCThe IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined…
- CVE-2022-475295 PoCsInsecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user…
- CVE-2022-475321 PoCFileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users§ion=cpanel&page=list request.
- CVE-2022-475471 PoCGossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though…
- CVE-2022-475771 PoCAn issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring…
- CVE-2022-475781 PoCAn issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring…
- CVE-2022-476152 PoCsWordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion
- CVE-2022-476313 PoCsRazer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privilege management.…
- CVE-2022-476322 PoCsRazer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and…
- CVE-2022-476362 PoCsA DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file…
- CVE-2022-476531 PoCGPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in eac3_update_channels function of media_tools/av_parsers.c:9113
- CVE-2022-476541 PoCGPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of…
- CVE-2022-476551 PoCLibde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback<unsigned short>
- CVE-2022-476561 PoCGPAC MP4box 2.1-DEV-rev617-g85ce76efd is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of…
- CVE-2022-476571 PoCGPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662
- CVE-2022-476581 PoCGPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function gf_hevc_read_vps_bs_internal of…
- CVE-2022-476591 PoCGPAC MP4box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to Buffer Overflow in gf_bs_read_data
- CVE-2022-476601 PoCGPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is has an integer overflow in isomedia/isom_write.c
- CVE-2022-476611 PoCGPAC MP4Box 2.1-DEV-rev649-ga8f438d20 is vulnerable to Buffer Overflow via media_tools/av_parsers.c:4988 in…
- CVE-2022-476621 PoCGPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite recursion in Media_GetSample…
- CVE-2022-476631 PoCGPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609
- CVE-2022-476641 PoCLibde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse
- CVE-2022-476651 PoCLibde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int, int, int)
- CVE-2022-476731 PoCAn issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a…
- CVE-2022-476951 PoCAn issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via…
- CVE-2022-476961 PoCAn issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via…
- CVE-2022-477141 PoCLast Yard 22.09.8-1 does not enforce HSTS headers
- CVE-2022-477151 PoCIn Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic.
- CVE-2022-477171 PoCLast Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).
- CVE-2022-477321 PoCIn Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and download it, revealing…
- CVE-2022-477582 PoCsNanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
- CVE-2022-477671 PoCA backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This…
- CVE-2022-478531 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacker can obtain a…
- CVE-2022-478541 PoCi-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.
- CVE-2022-478702 PoCsA Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to…
- CVE-2022-478721 PoCA Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via…
- CVE-2022-478742 PoCsImproper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections…
- CVE-2022-478752 PoCsA Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary…
- CVE-2022-478762 PoCsThe integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts.
- CVE-2022-478772 PoCsA Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in…
- CVE-2022-478782 PoCsIncorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to…
- CVE-2022-478791 PoCA Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP…
- CVE-2022-478801 PoCAn Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to…
- CVE-2022-479452 PoCsThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled…
- CVE-2022-479491 PoCThe Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to…
- CVE-2022-479521 PoClxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a…
- CVE-2022-4796610 PoCsKEVMultiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache…
- CVE-2022-479865 PoCsKEVIBM Aspera Faspex code execution