CVE-2022-48000 to CVE-2022-48999
57 CVEs with public proof-of-concept exploits.
- CVE-2022-480061 PoCAn arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This…
- CVE-2022-480111 PoCOpencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
- CVE-2022-480122 PoCsOpencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component…
- CVE-2022-480131 PoCOpencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component…
- CVE-2022-480191 PoCThe components wfshbr64.sys and wfshbr32.sys in Another Eden before v3.0.20 and before v2.14.200 allows attackers to perform privilege…
- CVE-2022-480631 PoCGNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function…
- CVE-2022-480641 PoCGNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function…
- CVE-2022-480651 PoCGNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c.
- CVE-2022-480781 PoCpycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component ASTree.cpp:BuildFromCode.
- CVE-2022-480791 PoCMonnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code…
- CVE-2022-480851 PoCSoftr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter.
- CVE-2022-480901 PoCTramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.
- CVE-2022-480911 PoCTramyardg hotel-mgmt-system version 2022.4 is vulnerable to Cross Site Scripting (XSS) via process_update_profile.php.
- CVE-2022-481071 PoCD-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This…
- CVE-2022-481081 PoCD-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask.…
- CVE-2022-481101 PoCCKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5 widget.…
- CVE-2022-481112 PoCsA cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows…
- CVE-2022-481131 PoCA vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted…
- CVE-2022-481141 PoCRuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
- CVE-2022-481161 PoCAyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php.
- CVE-2022-481211 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits parameter in the…
- CVE-2022-481221 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the…
- CVE-2022-481231 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the…
- CVE-2022-481241 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName parameter in the…
- CVE-2022-481251 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password parameter in the…
- CVE-2022-481261 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the…
- CVE-2022-481301 PoCTenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters…
- CVE-2022-481501 PoCShopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.
- CVE-2022-481521 PoCSQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive information via the id…
- CVE-2022-481643 PoCsAn access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers…
- CVE-2022-481651 PoCAn access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers…
- CVE-2022-481661 PoCAn access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log…
- CVE-2022-481772 PoCsX2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the…
- CVE-2022-481782 PoCsX2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action…
- CVE-2022-481941 PoCTP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service…
- CVE-2022-481973 PoCsReflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, TreeView component and…
- CVE-2022-482161 PoCUniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds.
- CVE-2022-482511 PoCThe AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the…
- CVE-2022-482521 PoCThe jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter) OS Command…
- CVE-2022-482533 PoCsnhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote…
- CVE-2022-482811 PoCprocessCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a…
- CVE-2022-483031 PoCGNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to…
- CVE-2022-483111 PoC**UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model…
- CVE-2022-483211 PoCSSRF in agent-receiver API
- CVE-2022-483231 PoCSunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and…
- CVE-2022-484291 PoCIn JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
- CVE-2022-484741 PoCControl de Ciber, in its 1.650 version, is affected by a Denial of Service condition through the version function. Sending a malicious…
- CVE-2022-484751 PoCBuffer Overflow vulnerability in Control de Ciber version 1.650, in the printing function. Sending a modified request by the attacker…
- CVE-2022-485471 PoCA reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject…
- CVE-2022-485541 PoCFile before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.
- CVE-2022-485601 PoCA use-after-free exists in Python through 3.9 via heappushpop in heapq.
- CVE-2022-485652 PoCsAn XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in…
- CVE-2022-486121 PoCA Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.7 allows remote attackers to inject…
- CVE-2022-486151 PoCAn improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial…
- CVE-2022-486161 PoCA Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability may allow…
- CVE-2022-486221 PoCIn GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in…
- CVE-2022-486561 PoCdmaengine: ti: k3-udma-private: Fix refcount leak bug in of_xudma_dev_get()