CVE-2022-4000 to CVE-2022-4999
483 CVEs with public proof-of-concept exploits.
- CVE-2022-40001 PoCWooCommerce Shipping - DPD baltic < 1.2.11 - Admin+ Stored XSS
- CVE-2022-40041 PoCDonation Button <= 4.0.0 - Subscriber+ Broken Access Control leading to SMS Spam
- CVE-2022-40051 PoCDonation Button <= 4.0.0 - Contributor+ Stored XSS
- CVE-2022-40101 PoCImage Hover Effects < 5.5 - Admin+ Stored XSS
- CVE-2022-40121 PoCHospital Management Center patient-info.php sql injection
- CVE-2022-40131 PoCHospital Management Center appointment.php cross-site request forgery
- CVE-2022-40151 PoCSports Club Management System make_payments.php sql injection
- CVE-2022-40161 PoCBooster for WooCommerce - Custom Role Creation/Deletion via CSRF
- CVE-2022-40171 PoCBooster for WooCommerce - Multiple CSRF
- CVE-2022-40181 PoCMissing Authentication for Critical Function in ikus060/rdiffweb
- CVE-2022-40231 PoC3DPrint < 3.5.6.9 - CSRF to arbitrary file downlad
- CVE-2022-40241 PoCPie Register < 3.8.1.3 - Unauthenticated Arbitrary User Deletion
- CVE-2022-40341 PoCAppointment Hour Booking <= 1.3.72 - CSV Injection
- CVE-2022-40421 PoCPaytium < 4.3.7 - Admin+ Stored XSS
- CVE-2022-40431 PoCWP Custom Admin Interface < 7.29 - Admin+ PHP Object Injection
- CVE-2022-40472 PoCsReturn Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
- CVE-2022-40492 PoCsWP User <= 7.0 - Unauthenticated SQLi
- CVE-2022-40502 PoCsJoomSport < 5.2.8 - Unauthenticated SQLi
- CVE-2022-40511 PoCHostel Searching Project view-property.php sql injection
- CVE-2022-40572 PoCsAutoptimize < 3.1.0 - Sensitive Data Disclosure
- CVE-2022-40581 PoCPhoto Gallery < 1.8.3 - Stored XSS via CSRF
- CVE-2022-40592 PoCsCryptocurrency Widgets Pack < 2.0 - Unauthenticated SQLi
- CVE-2022-40604 PoCsUser Post Gallery <= 2.19 - Unauthenticated RCE
- CVE-2022-40613 PoCsJobBoardWP < 1.2.2 - Unauthenticated Arbitrary File Upload
- CVE-2022-40632 PoCsInPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
- CVE-2022-40641 PoCDalli Meta Protocol request_formatter.rb self.meta_set injection
- CVE-2022-40651 PoCcbeust testng XML File Parser JarFileUtils.java testngXmlExistsInJar path traversal
- CVE-2022-40681 PoCImproperly Controlled Modification of Dynamically-Determined Object Attributes in librenms/librenms
- CVE-2022-40881 PoCrickxy Stock Management System processlogin.php sql injection
- CVE-2022-40891 PoCrickxy Stock Management System processlogin.php cross site scripting
- CVE-2022-40901 PoCrickxy Stock Management System cross-site request forgery
- CVE-2022-40931 PoCSQL Injection in dolibarr/dolibarr
- CVE-2022-40962 PoCsServer-Side Request Forgery (SSRF) in appsmithorg/appsmith
- CVE-2022-40971 PoCAll In One WP Security & Firewall < 5.0.8 - IP Spoofing
- CVE-2022-40991 PoCJoy Of Text Lite < 2.3.1 - Unauthenticated SQLi
- CVE-2022-41011 PoCImages Optimize and Upload CF7 <= 2.1.4 - Unauthenticated Arbitrary File Deletion
- CVE-2022-41021 PoCRoyal Elementor Addons < 1.3.56 - Subscriber+ Arbitrary Post Deletion
- CVE-2022-41031 PoCRoyal Elementor Addons < 1.3.56 - Subscriber+ Arbitrary Post Creation
- CVE-2022-41041 PoCA loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compression tool, resulting…
- CVE-2022-41051 PoCCross-site Scripting (XSS) - Stored in kiwitcms/kiwi
- CVE-2022-41061 PoCWholesale Market for WooCommerce < 1.0.7 - Unauthenticated Arbitrary File Download
- CVE-2022-41071 PoCSMSA Shipping for WooCommerce < 1.0.5 - Subscriber+ Arbitrary File Download
- CVE-2022-41081 PoCWholesale Market for WooCommerce < 1.0.8 - Admin+ Arbitrary File Download
- CVE-2022-41091 PoCWholesale Market for WooCommerce < 2.0.0 - Admin+ Arbitrary Log Download
- CVE-2022-41101 PoCEventify <= 2.1 - Admin+ Stored XSS
- CVE-2022-41111 PoCImproper Validation of Specified Quantity in Input in tooljet/tooljet
- CVE-2022-41121 PoCQuizlord <= 2.0 - Admin+ Stored XSS
- CVE-2022-41141 PoCSuperio - Job Board < 1.2.33 - Subscriber+ Stored Cross-Site Scripting
- CVE-2022-41151 PoCEditorial Calendar < 3.8.3 - Contributor+ Stored XSS
- CVE-2022-41172 PoCsIWS - Geo Form Fields <= 1.0 - Unauthenticated SQLi
- CVE-2022-41181 PoCBitcoin / AltCoin Payment Gateway <= 1.7.1 - Unauthenticated SQLi
- CVE-2022-41191 PoCImage Optimizer, Resizer and CDN < 6.8.1 - Admin+ Stored XSS
- CVE-2022-41201 PoCStop Spammers Security < 2022.6 - Unauthenticated PHP Object Injection
- CVE-2022-41211 PoCIn libetpan a null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c was found that could lead…
- CVE-2022-41241 PoCPopup Manager <= 1.6.6 - Unauthenticated Arbitrary Popup Deletion
- CVE-2022-41251 PoCPopup Manager <= 1.6.6 - Unauthenticated Stored XSS
- CVE-2022-41361 PoCExposed Dangerous Method or Function in qmpaas/leadshop
- CVE-2022-41371 PoCKeycloak: reflected xss attack
- CVE-2022-41402 PoCsWelcart e-Commerce < 2.8.5 - Unauthenticated Arbitrary File Access
- CVE-2022-41411 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2022-41421 PoCWordPress Filter Gallery Plugin < 0.1.6 - Admin+ Stored XSS
- CVE-2022-41481 PoCWP OAuth Server < 4.3.0 - Subscriber+ Arbitrary Client Deletion
- CVE-2022-41502 PoCsContest Gallery < 19.1.5 - Author+ SQL Injection
- CVE-2022-41512 PoCsContest Gallery < 19.1.5 - Admin+ SQL Injection
- CVE-2022-41522 PoCsContest Gallery < 19.1.5 - Author+ SQL Injection
- CVE-2022-41532 PoCsContest Gallery < 19.1.5.1 - Author+ SQL Injection
- CVE-2022-41542 PoCsContest Gallery Pro < 19.1.5 - Admin+ SQL Injection
- CVE-2022-41552 PoCsContest Gallery < 19.1.5 - Admin+ SQL Injection
- CVE-2022-41562 PoCsContest Gallery < 19.1.5.1 - Unauthenticated SQL Injection
- CVE-2022-41572 PoCsContest Gallery < 19.1.5 - Admin+ SQL Injection
- CVE-2022-41582 PoCsContest Gallery < 19.1.5 - Unauthenticated SQL Injection
- CVE-2022-41592 PoCsContest Gallery < 19.1.5.1 - Author+ SQL Injection
- CVE-2022-41602 PoCsContest Gallery < 19.1.5 - Author+ SQL Injection
- CVE-2022-41612 PoCsContest Gallery < 19.1.5 - Author+ SQL Injection
- CVE-2022-41622 PoCsContest Gallery < 19.1.5 - Author+ SQL Injection
- CVE-2022-41632 PoCsContest Gallery < 19.1.5 - Author+ SQL Injection
- CVE-2022-41642 PoCsContest Gallery < 19.1.5 - Author+ SQL Injection
- CVE-2022-41652 PoCsContest Gallery < 19.1.5 - Author+ SQL Injection
- CVE-2022-41662 PoCsContest Gallery < 19.1.5 - Author+ SQL Injection
- CVE-2022-41741 PoCType confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2022-41961 PoCMulti Step Form < 1.7.8 - Admin+ Stored XSS
- CVE-2022-41971 PoCSliderby10Web < 1.2.53 - Admin+ Stored XSS
- CVE-2022-41981 PoCWP Social Sharing <= 2.2 - Admin+ Stored XSS
- CVE-2022-41991 PoCLink Library < 7.4.1 - Admin+ Stored XSS
- CVE-2022-42001 PoCLogin with Cognito <= 1.4.8 - Admin+ Stored XSS
- CVE-2022-42011 PoCA blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to…
- CVE-2022-42021 PoCGPAC lsr_dec.c lsr_translate_coords integer overflow
- CVE-2022-42081 PoCChained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via datef
- CVE-2022-42091 PoCChained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via pointsf
- CVE-2022-42101 PoCChained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via dnf
- CVE-2022-42111 PoCChained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via emailf
- CVE-2022-42121 PoCChained Quiz <= 1.3.2 - Reflected Cross-Site Scripting via ipf
- CVE-2022-42141 PoCChained Quiz <= 1.3.2.3 - Reflected Cross-Site Scripting via ip
- CVE-2022-42151 PoCChained Quiz <= 1.3.2.3 - Reflected Cross-Site Scripting via date
- CVE-2022-42161 PoCChained Quiz <= 1.3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Facebook App ID
- CVE-2022-42171 PoCChained Quiz <= 1.3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Mailchimp API Key
- CVE-2022-42181 PoCChained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Arbitrary Quiz Deletion and Copying
- CVE-2022-42191 PoCChained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Submitted Response Deletion
- CVE-2022-42201 PoCChained Quiz <= 1.3.2.4 - Cross-Site Request Forgery to Question Deletion
- CVE-2022-42232 PoCsThe pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities…
- CVE-2022-42261 PoCSimple Basic Contact Form < 20221201 - Admin+ Stored XSS
- CVE-2022-42271 PoCBooster for WooCommerce - Reflected Cross-Site Scripting
- CVE-2022-42281 PoCSourceCodester Book Store Management System information disclosure
- CVE-2022-42291 PoCSourceCodester Book Store Management System index.php access control
- CVE-2022-42301 PoCWP Statistics < 13.2.9 - Authenticated SQLi
- CVE-2022-42311 PoCTribal Systems Zenario CMS Remember Me session fixiation
- CVE-2022-42351 PoCRushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is…
- CVE-2022-42361 PoCWelcart e-Commerce < 2.8.5 - Subscriber+ Arbitrary File Access
- CVE-2022-42371 PoCWelcart e-Commerce < 2.8.6 - Subscriber+ PHAR Deserialisation
- CVE-2022-42391 PoCWorkreap < 2.6.4 - Subscriber+ Arbitrary Posts Deletion via IDOR
- CVE-2022-42421 PoCWP Google Review Slider < 11.6 - Admin+ Stored XSS
- CVE-2022-42431 PoCImageInject <= 1.17 - Admin+ Stored XSS
- CVE-2022-42441 PoCCodehaus-plexus: directory traversal
- CVE-2022-42471 PoCMovie Ticket Booking System booking.php sql injection
- CVE-2022-42481 PoCMovie Ticket Booking System editBooking.php sql injection
- CVE-2022-42501 PoCMovie Ticket Booking System booking.php cross site scripting
- CVE-2022-42511 PoCMovie Ticket Booking System editBooking.php cross site scripting
- CVE-2022-42561 PoCAll-in-One Addons for Elementor - WidgetKit < 2.4.4 - Admin+ Stored XSS
- CVE-2022-42602 PoCsWP-Ban < 1.69.1 - Admin+ Stored XSS
- CVE-2022-42623 PoCsKEVType confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2022-42651 PoCReplyable < 2.2.10 - Subscriber+ PHP Object Injection
- CVE-2022-42661 PoCBulk Delete Users by Email <= 1.2 - User Deletion via CSRF
- CVE-2022-42671 PoCBulk Delete Users by Email <= 1.2 - Reflected Cross-Site Scripting
- CVE-2022-42682 PoCsPlugin Logic < 1.0.8 - Admin+ SQLi
- CVE-2022-42711 PoCCross-site Scripting (XSS) - Reflected in osticket/osticket
- CVE-2022-42721 PoCFeMiner wms unrestricted upload
- CVE-2022-42731 PoCSourceCodester Human Resource Management System Content-Type employee.php unrestricted upload
- CVE-2022-42741 PoCHouse Rental System view-property.php sql injection
- CVE-2022-42751 PoCHouse Rental System POST Request search-property.php sql injection
- CVE-2022-42761 PoCHouse Rental System POST Request tenant-engine.php unrestricted upload
- CVE-2022-42781 PoCSourceCodester Human Resource Management System employeeadd.php sql injection
- CVE-2022-42791 PoCSourceCodester Human Resource Management System employeeview.php cross site scripting
- CVE-2022-42851 PoCAn illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may…
- CVE-2022-42921 PoCUse After Free in vim/vim
- CVE-2022-42931 PoCFloating Point Comparison with Incorrect Operator in vim/vim
- CVE-2022-42952 PoCsShow All Comments < 7.0.1 - Reflected XSS
- CVE-2022-42961 PoCTP-Link TL-WR740N ARP resource consumption
- CVE-2022-42972 PoCsWP AutoComplete Search <= 1.0.4 - Unauthenticated SQLi
- CVE-2022-42982 PoCsWholesale Market < 2.2.1 - Unauthenticated Arbitrary File Download
- CVE-2022-42991 PoCMetricool < 1.18 - Admin+ Stored XSS
- CVE-2022-43012 PoCsSunshine Photo Cart < 2.9.15 - Reflected XSS
- CVE-2022-43021 PoCWhite Label CMS < 2.5 - Admin+ PHP Object Injection
- CVE-2022-43031 PoCWP Limit Login Attempts <= 2.6.4 - IP Spoofing
- CVE-2022-43041 PoCTiming Oracle in RSA Decryption
- CVE-2022-43052 PoCsLogin as User or Customer < 3.3 - Unauthenticated Privilege Escalation to Admin
- CVE-2022-43062 PoCsPanda Pods Repeater Field < 1.5.4 - Reflected XSS
- CVE-2022-43071 PoCPardakht Delkhah < 2.9.3 - Unauthenticated Stored XSS
- CVE-2022-43091 PoCSubscribe2 < 10.38 - User Deletion via CSRF
- CVE-2022-43101 PoCSlimstat Analytics < 4.9.3 - Unauthenticated Stored XSS
- CVE-2022-43141 PoCImproper Privilege Management in ikus060/rdiffweb
- CVE-2022-43171 PoCAn issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request…
- CVE-2022-43202 PoCsWordPress Events Calendar Plugin < 1.4.5 - Multiple Reflected XSS
- CVE-2022-43212 PoCsPDF Generator for WordPress < 1.1.2 - Reflected XSS
- CVE-2022-43231 PoCGoogle Analyticator < 6.5.6 - Admin+ PHP Object Injection
- CVE-2022-43241 PoCCustom Field Template < 2.5.8 - Admin+ PHP Object Injection
- CVE-2022-43252 PoCsPost Status Notifier Lite < 1.10.1 - Reflected XSS
- CVE-2022-43282 PoCsWooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File Upload
- CVE-2022-43291 PoCProduct list Widget for Woocommerce <= 1.0 - Reflected XSS
- CVE-2022-43301 PoCWP Attachments < 5.0.6 - Admin+ Stored XSS
- CVE-2022-43351 PoCA blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1…
- CVE-2022-43401 PoCBookingPress < 1.0.31 - Unauthenticated IDOR in appointment_id
- CVE-2022-43431 PoCExposure of Sensitive Information to an Unauthorized Actor in GitLab
- CVE-2022-43461 PoCAll In One WP Security & Firewall < 5.1.3 - Configuration Leak
- CVE-2022-43481 PoCy_project RuoYi-Cloud JSON cross site scripting
- CVE-2022-43491 PoCCTF-hacker pwn delete.html cross-site request forgery
- CVE-2022-43511 PoCQe SEO Handyman <= 1.0 - Admin+ SQLi
- CVE-2022-43521 PoCQe SEO Handyman <= 1.0 - Admin+ SQLi
- CVE-2022-43551 PoCLetsRecover < 1.2.0 - Admin+ SQLi
- CVE-2022-43561 PoCLetsRecover < 1.2.0 - Admin+ SQLi
- CVE-2022-43571 PoCLetsRecover < 1.2.0 - Unauthenticated SQLi
- CVE-2022-43581 PoCWP RSS By Publishers <= 0.1 - Admin+ SQLi
- CVE-2022-43591 PoCWP RSS By Publishers <= 0.1 - Admin+ SQLi
- CVE-2022-43601 PoCWP RSS By Publishers <= 0.1 - Admin+ SQLi
- CVE-2022-43612 PoCsKeycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC…
- CVE-2022-43621 PoCPopup Maker < 1.16.9 - Contributor+ Stored XSS via Shortcode
- CVE-2022-43631 PoCWholesale Market <= 2.2.2 - Settings Update via CSRF
- CVE-2022-43641 PoCTeledyne FLIR AX8 Web Service palette.php command injection
- CVE-2022-43661 PoCMissing Authorization in lirantal/daloradius
- CVE-2022-43681 PoCWP CSV <= 1.8.0.0 - Reflected XSS via CSV Import
- CVE-2022-43691 PoCWP-Lister Lite for Amazon < 2.4.4 - Reflected XSS
- CVE-2022-43702 PoCsMultimedial Images <= 1.0b - Admin+ SQLi
- CVE-2022-43712 PoCsWeb Invoice <= 2.1.3 - Authenticated SQLi
- CVE-2022-43722 PoCsWeb Invoice <= 2.1.3 - Authenticated SQLi
- CVE-2022-43731 PoCQuote-O-Matic <= 1.0.5 - Admin+ SQLi
- CVE-2022-43741 PoCBg Bible References <= 3.8.14 - Reflected XSS
- CVE-2022-43753 PoCsMingsoft MCMS list sql injection
- CVE-2022-43811 PoCPopup Maker < 1.16.9 - Contributor+ Stored XSS via Subscription Form
- CVE-2022-43831 PoCCBX Petition for WordPress <= 1.0.3 - Unauthenticated SQLi
- CVE-2022-43841 PoCStream < 3.9.2 - Subscriber+ Alert Creation
- CVE-2022-43851 PoCIntuitive Custom Post Order < 3.1.4 - Subscriber+ Arbitrary Menu Order Update
- CVE-2022-43861 PoCIntuitive Custom Post Order < 3.1.4 - Arbitrary Menu Order Update via CSRF
- CVE-2022-43911 PoCVision Interactive For WordPress <= 1.5.3 - Contributor+ Stored XSS
- CVE-2022-43921 PoCiPanorama 360 WordPress Virtual Tour Builder <= 1.6.29 - Contributor+ Stored XSS
- CVE-2022-43931 PoCImageLinks Interactive Image Builder for WordPress <= 1.5.3 - Contributor+ Stored XSS
- CVE-2022-43941 PoCiPages Flipbook For WordPress <= 1.4.6 - Contributor+ Stored XSS
- CVE-2022-43953 PoCsMembership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
- CVE-2022-44031 PoCSourceCodester Canteen Management System ajax_represent.php sql injection
- CVE-2022-44071 PoCCross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
- CVE-2022-44081 PoCCross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
- CVE-2022-44091 PoCSensitive Cookie in HTTPS Session Without 'Secure' Attribute in thorsten/phpmyfaq
- CVE-2022-44131 PoCCross-site Scripting (XSS) - Reflected in nuxt/framework
- CVE-2022-44171 PoCWP Cerber < 9.3.3 - User Enumeration Bypass via Rest API
- CVE-2022-44261 PoCMautic Integration For WooCommerce < 1.0.3 - Arbitrary Options Update via CSRF
- CVE-2022-44312 PoCsWOOCS < 1.3.9.4 - Contributor+ Stored XSS
- CVE-2022-44421 PoCWCK < 2.3.3 - Admin+ Stored XSS
- CVE-2022-44431 PoCBruteBank - WP Security & Firewall < 1.9 - Settings Update via CSRF
- CVE-2022-44451 PoCFL3R FeelBox <= 8.1 - Unauthenticated SQLi
- CVE-2022-44461 PoCPHP Remote File Inclusion in tsolucio/corebos
- CVE-2022-44472 PoCsFontsy <= 1.8.6 - Multiple Unauthenticated SQLi
- CVE-2022-44481 PoCGiveWP < 2.24.0 - Contributor+ Stored XSS
- CVE-2022-44491 PoCPage Scroll To ID < 1.7.6 - Contributor+ Stored XSS
- CVE-2022-44511 PoCSassy Social Share < 3.3.45 - Contributor+ Stored XSS
- CVE-2022-44531 PoC3D FlipBook <= 1.13.2 - Contributor+ Stored XSS
- CVE-2022-44581 PoCAmr Shortcode Any Widget <= 4.0 - Contributor+ Stored XSS
- CVE-2022-44591 PoCWP Show Posts < 1.1.4 - Contributor+ Stored XSS
- CVE-2022-44601 PoCSidebar Widgets by CodeLights <= 1.4 - Contributor+ Stored XSS
- CVE-2022-44641 PoCThemify Portfolio Post < 1.2.1 - Contributor+ Stored XSS
- CVE-2022-44651 PoCWP Video Lightbox < 1.9.7 - Contributor+ Stored XSS
- CVE-2022-44661 PoCWordPress Infinite Scroll - Ajax Load More < 5.6.0.3 - Contributor+ Stored XSS
- CVE-2022-44671 PoCSearch & Filter < 1.2.16 - Contributor+ Stored XSS
- CVE-2022-44681 PoCWP Recipe Maker < 8.6.1 - Contributor+ Stored XSS
- CVE-2022-44691 PoCSimple Membership < 4.2.2 - Contributor+ Stored XSS
- CVE-2022-44701 PoCWidgets for Google Reviews < 9.8 - Contributor+ Stored XSS
- CVE-2022-44711 PoCYARPP - Yet Another Related Posts Plugin < 5.30.3 - Contributor+ Stored XSS
- CVE-2022-44721 PoCSimple Sitemap < 3.5.8 - Contributor+ Stored XSS
- CVE-2022-44731 PoCWidget Shortcode <= 0.3.5 - Contributor+ Stored XSS
- CVE-2022-44741 PoCEasy Social Feed – Social Photos Gallery – Post Feed – Like Box < 6.4.0 - Contributor+ Stored XSS
- CVE-2022-44751 PoCCollapse-O-Matic < 1.8.3 - Contributor+ Stored XSS
- CVE-2022-44761 PoCDownload Manager < 3.2.62 - Contributor+ Stored XSS
- CVE-2022-44771 PoCSmash Balloon Social Post Feed < 4.1.6 - Contributor+ Stored XSS
- CVE-2022-44781 PoCFont Awesome < 4.3.2 - Contributor+ Stored XSS
- CVE-2022-44791 PoCTable of Contents Plus < 2212 - Contributor+ Stored XSS
- CVE-2022-44801 PoCClick to Chat < 3.18.1 - Contributor+ Stored XSS
- CVE-2022-44811 PoCMesmerize Companion < 1.6.135 - Contributor+ Stored XSS
- CVE-2022-44821 PoCCarousel, Slider, Gallery by WP Carousel < 2.5.3 - Contributor+ Stored XSS
- CVE-2022-44831 PoCInsert Pages < 3.7.5 - Contributor+ Stored XSS
- CVE-2022-44841 PoCSuper Socializer < 7.13.44 - Contributor+ Stored XSS
- CVE-2022-44851 PoCPage-list < 5.3 - Contributor+ Stored XSS
- CVE-2022-44861 PoCMeteor Slides < 1.5.7 - Contributor+ Stored XSS
- CVE-2022-44871 PoCEasy Accordion < 2.2.0 - Contributor+ Stored XSS
- CVE-2022-44881 PoCWidgets on Pages < 1.8.0 - Contributor+ Stored XSS
- CVE-2022-44891 PoCWOOF - Products Filter for WooCommerce < 1.3.2 - Admin+ PHP Object Injection
- CVE-2022-44911 PoCWP Table Reloaded <= 1.9.4 - Contributor+ Stored XSS
- CVE-2022-44963 PoCsminiOrange WordPress SAML SSO multiple versions - Open Redirect in SSO login
- CVE-2022-44971 PoCJetpack CRM < 5.5 - Contributor+ Stored XSS
- CVE-2022-45021 PoCCross-site Scripting (XSS) - Reflected in openemr/openemr
- CVE-2022-45031 PoCCross-site Scripting (XSS) - Generic in openemr/openemr
- CVE-2022-45041 PoCImproper Input Validation in openemr/openemr
- CVE-2022-45051 PoCAuthorization Bypass Through User-Controlled Key in openemr/openemr
- CVE-2022-45061 PoCUnrestricted Upload of File with Dangerous Type in openemr/openemr
- CVE-2022-45071 PoCReal Cookie Banner < 3.4.10 - Contributor+ Stored XSS
- CVE-2022-45081 PoCConvertKit < 2.0.5 - Contributor+ Stored XSS
- CVE-2022-45091 PoCContent Control < 1.1.10 - Contributor+ Stored XSS
- CVE-2022-45106 PoCsPath Traversal in binwalk
- CVE-2022-45121 PoCBetter Font Awesome < 2.0.4 - Contributor+ Stored XSS
- CVE-2022-45391 PoCWeb Application Firewall <= 2.1.2 - IP Address Spoofing to Protection Mechanism Bypass
- CVE-2022-45421 PoCCompact WP Audio Player < 1.9.8 - Contributor+ Stored XSS
- CVE-2022-45432 PoCsA flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR…
- CVE-2022-45441 PoCMashShare < 3.8.7 - Contributor+ Stored XSS
- CVE-2022-45451 PoCSitemap < 4.4 - Contributor+ Stored XSS
- CVE-2022-45461 PoCMapwiz <= 1.0.1 - Admin+ SQLi
- CVE-2022-45471 PoCConditional Payment Methods for WooCommerce <= 1.0 - Admin+ SQLi
- CVE-2022-45481 PoCOptimize images ALT Text (alt tag) & names for SEO using AI < 2.0.8 - Settings Update via CSRF
- CVE-2022-45491 PoCTickera < 3.5.1.0 - Plugin Data Deletion via CSRF
- CVE-2022-45501 PoCUser Activity <= 1.0.1 - IP Spoofing
- CVE-2022-45511 PoCRich Table of Contents < 1.3.9 - Contributor+ Stored XSS
- CVE-2022-45521 PoCFL3R FeelBox <= 8.1 - Settings Update via CSRF to Stored XSS
- CVE-2022-45531 PoCFL3R FeelBox <= 8.1 - Moods Reset via CSRF
- CVE-2022-45561 PoCAlinto SOGo Identity SOGoUserDefaults.m _migrateMailIdentities cross site scripting
- CVE-2022-45621 PoCMeks Flexible Shortcodes < 1.3.5 - Contributor+ Stored XSS
- CVE-2022-45662 PoCsy_project RuoYi GenController sql injection
- CVE-2022-45671 PoCImproper Access Control in openemr/openemr
- CVE-2022-45701 PoCTop 10 < 3.2.3 - Contributor+ Stored XSS
- CVE-2022-45711 PoCSeriously Simple Podcasting < 2.19.1 - Contributor+ Stored XSS
- CVE-2022-45761 PoCEasy Bootstrap Shortcode <= 4.5.4 - Contributor+ Stored XSS
- CVE-2022-45771 PoCEasy Testimonials < 3.9.3 - Contributor+ Stored XSS
- CVE-2022-45781 PoCVideo Conferencing with Zoom < 4.0.10 - Contributor+ Stored XSS
- CVE-2022-45801 PoCTwenty20 Image Before-After <= 1.5.9 - Contributor+ Stored XSS
- CVE-2022-45841 PoCAxiomatic Bento4 mp42aac heap-based overflow
- CVE-2022-45961 PoCShoplazza Add Blog Post cross site scripting
- CVE-2022-45971 PoCShoplazza LifeStyle Create Product v2_products cross site scripting
- CVE-2022-45981 PoCShoplazza LifeStyle Announcement cross site scripting
- CVE-2022-45991 PoCShoplazza LifeStyle Product cross site scripting
- CVE-2022-46001 PoCShoplazza LifeStyle Product Carousel cross site scripting
- CVE-2022-46011 PoCShoplazza LifeStyle Shipping/Member Discount/Icon cross site scripting
- CVE-2022-46021 PoCShoplazza LifeStyle Review Flow cross site scripting
- CVE-2022-46051 PoCCross-site Scripting (XSS) - Stored in flatpressblog/flatpress
- CVE-2022-46061 PoCPHP Remote File Inclusion in flatpressblog/flatpress
- CVE-2022-46091 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2022-46101 PoCClick Studios Passwordstate risky encryption
- CVE-2022-46113 PoCsClick Studios Passwordstate hard-coded credentials
- CVE-2022-46121 PoCClick Studios Passwordstate insufficiently protected credentials
- CVE-2022-46131 PoCClick Studios Passwordstate Browser Extension Provisioning improper authorization
- CVE-2022-46141 PoCCross-site Scripting (XSS) - Stored in alagrede/znote-app
- CVE-2022-46151 PoCCross-site Scripting (XSS) - Reflected in openemr/openemr
- CVE-2022-46161 PoCThe webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This…
- CVE-2022-46171 PoCCross-site Scripting (XSS) - Reflected in microweber/microweber
- CVE-2022-46221 PoCLogin Logout Menu <= 1.3.3 - Contributor+ Stored XSS in Shortcode
- CVE-2022-46231 PoCND Shortcodes < 7.0 - Contributor+ Stored XSS via Shortcodes
- CVE-2022-46241 PoCGS Logo Slider < 3.3.8 - Contributor+ Stored XSS in Shortcode
- CVE-2022-46251 PoCLogin Logout Menu < 1.4.0 - Contributor+ Stored XSS in Shortcode
- CVE-2022-46261 PoCPPWP – WordPress Password Protect Page < 1.8.6 - Contributor+ Stored XSS in Shortcode
- CVE-2022-46271 PoCShiftNav – Responsive Mobile Menu < 1.7.2 - Contributor+ Stored XSS in Shortcode
- CVE-2022-46281 PoCEasy PayPal Buy Now Button < 1.7.4 - Contributor+ Stored XSS in Shortcode
- CVE-2022-46291 PoCProduct Slider for WooCommerce < 2.6.4 - Contributor+ Stored XSS in Shortcode
- CVE-2022-46301 PoCSensitive Cookie Without 'HttpOnly' Flag in lirantal/daloradius
- CVE-2022-46401 PoCMingsoft MCMS Article save cross site scripting
- CVE-2022-46441 PoCOpen Redirect in ikus060/rdiffweb
- CVE-2022-46451 PoCLibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted…
- CVE-2022-46481 PoCReal Testimonials < 2.6.0 - Contributor+ Stored XSS
- CVE-2022-46491 PoCWP Extended Search < 2.1.2 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46501 PoCHashBar – WordPress Notification Bar < 1.3.6 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46511 PoCJustified Gallery < 1.7.1 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46521 PoCVideo Background < 2.7.5 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46531 PoCGreenshift – animation and page builder blocks < 4.8.9 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46541 PoCPricing Tables WordPress Plugin – Easy Pricing Tables < 3.2.3 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46551 PoCWelcart e-Commerce < 2.8.9 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46561 PoCWP Visitor Statistics (Real Time Traffic) < 6.5 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46571 PoCRestaurant Menu < 2.3.6 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46581 PoCRSSImport <= 4.6.1 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46611 PoCWoo Products Widgets For Elementor < 1.0.8 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46641 PoCLogo Slider < 3.6.0 - Contributor+ Stored XSS in Shortcode
- CVE-2022-46651 PoCUnrestricted Upload of File with Dangerous Type in ampache/ampache
- CVE-2022-46661 PoCMarkup <= 4.8.1 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46671 PoCRSS Aggregator by Feedzy < 4.1.1 - Contributor+ Stored XSS
- CVE-2022-46681 PoCEasy Appointments < 3.11.2 - Contributor+ Stored XSS in Shortcode
- CVE-2022-46691 PoCPage Builder: Live Composer < 1.5.23 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46701 PoCPDF.js Viewer < 2.1.8 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46711 PoCPixCodes < 2.3.7 - Contributor+ Stored XSS in Shortcode
- CVE-2022-46721 PoCWordPress Simple Shopping Cart < 4.6.2 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46731 PoCRate my Post – WP Rating System < 3.3.9 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46741 PoCIbtana – WordPress Website Builder < 1.1.8.8 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46751 PoCMongoose Page Plugin < 1.9.0 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46761 PoCOSM – OpenStreetMap <= 6.01 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46771 PoCLeaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) < 3.12.7 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46781 PoCTemplatesNext ToolKit < 3.2.8 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46791 PoCWufoo Shortcode < 1.52 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46801 PoCRevive Old Posts – Social Media Auto Post and Scheduling Plugin < 9.0.11 - PHP Object Injection
- CVE-2022-46812 PoCsHide My WP < 6.2.9 - Unauthenticated SQLi
- CVE-2022-46821 PoCLightbox Gallery < 0.9.5 - Contributor+ Stored XSS via Shortcode
- CVE-2022-46831 PoCSensitive Cookie in HTTPS Session Without 'Secure' Attribute in usememos/memos
- CVE-2022-46861 PoCAuthorization Bypass Through User-Controlled Key in usememos/memos
- CVE-2022-46871 PoCIncorrect Use of Privileged APIs in usememos/memos
- CVE-2022-46891 PoCImproper Access Control in usememos/memos
- CVE-2022-46901 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2022-46911 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2022-46921 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2022-46931 PoCUser Verification < 1.0.94 - Authentication Bypass
- CVE-2022-46941 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2022-46951 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2022-46991 PoCMediaElement.js – HTML5 Video & Audio Player <= 4.2.8 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47061 PoCGenesis Columns Advanced < 2.0.4 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47141 PoCWP Dark Mode < 4.0.0 - Contributor+ Stored XSS in Shortcode
- CVE-2022-47151 PoCStructured Content < 1.5.1 - Contributor+ Stored XSS in Shortcode
- CVE-2022-47161 PoCWP Popups < 2.1.4.8 - Contributor+ Stored XSS
- CVE-2022-47171 PoCStrong Testimonials < 3.0.3 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47181 PoCLanding Page Builder < 1.4.9.9 - Contributor+ Cross-Site Scripting via Shortcode
- CVE-2022-47191 PoCBusiness Logic Errors in ikus060/rdiffweb
- CVE-2022-47201 PoCOpen Redirect in ikus060/rdiffweb
- CVE-2022-47211 PoCFailure to Sanitize Special Elements into a Different Plane (Special Element Injection) in ikus060/rdiffweb
- CVE-2022-47221 PoCAuthentication Bypass by Primary Weakness in ikus060/rdiffweb
- CVE-2022-47231 PoCAllocation of Resources Without Limits or Throttling in ikus060/rdiffweb
- CVE-2022-47241 PoCImproper Access Control in ikus060/rdiffweb
- CVE-2022-47321 PoCUnrestricted Upload of File with Dangerous Type in microweber/microweber
- CVE-2022-47331 PoCCross-site Scripting (XSS) - Stored in openemr/openemr
- CVE-2022-47401 PoCkkFileView picturesPreview setWatermarkAttribute cross site scripting
- CVE-2022-47451 PoCWP Customer Area < 8.1.4 - Unauthorised Actions via CSRF
- CVE-2022-47461 PoCFluentAuth < 1.0.2 - Bypass blocks by IP Spoofing
- CVE-2022-47471 PoCPost Category Image With Grid and Slider < 1.4.8 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47491 PoCPosts List Designer by Category < 3.2 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47501 PoCWP Responsive Testimonials Slider And Widget <= 1.5 - Contributor+ Stored XSS
- CVE-2022-47511 PoCWord Balloon < 4.19.3 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47521 PoCOpening Hours <= 2.3.0 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47531 PoCPrint-O-Matic < 2.1.8 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47541 PoCEasy Social Box <= 4.1.2 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47561 PoCYouTube Channel < 3.23.0 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47571 PoCList Pages Shortcode < 1.7.6 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47581 PoC10WebMapBuilder < 1.0.72 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47591 PoCGigPress < 2.3.28 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47601 PoCOneClick Chat to Order < 1.0.4.2 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47611 PoCPost Views Count <= 3.0.2 - Contributor+ Stored XSS in Shortcode
- CVE-2022-47621 PoCMaterialis Companion < 1.3.40 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47631 PoCIcon Widget < 1.3.0 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47641 PoCSimple File Downloader <= 1.0.4 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47651 PoCPortfolio for Elementor, Image Gallery & Post Grid | PowerFolio < 2.3.1 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47741 PoCBit Form < 1.9 - RCE via Unauthenticated Arbitrary File Upload
- CVE-2022-47751 PoCGeoDirectory < 2.2.22 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47761 PoCCC Child Pages < 1.43 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47771 PoCBootstrap Shortcodes <= 3.4.0 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47811 PoCAccordion Shortcodes <= 2.4.2 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47821 PoCClickFunnels <= 3.1.1 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47831 PoCYoutube Channel Gallery <= 2.4 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47841 PoCHueman Addons <= 2.3.3 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47851 PoCDownload Video Sidebar Widgets <= 6.1 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47861 PoCVideo.js - HTML5 Video Player for WordPress <= 4.5.0 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47871 PoCThemify Shortcodes < 2.0.8 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47881 PoCEmbed PDF <= 1.0.6 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47891 PoCWPZOOM Portfolio < 1.2.2 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47901 PoCWP Google My Business Auto Publish < 3.4 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47911 PoCProduct Slider and Carousel with Category for WooCommerce < 2.8 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47921 PoCNews & Blog Designer Pack < 3.3 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47931 PoCBlog Designer – Post and Widget < 2.4.1 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47941 PoCAAWP < 3.12.3 - Unsafe URL Handling
- CVE-2022-47951 PoCGalleries by Angie Makes <= 1.67 - Contributor+ Stored XSS via Shortcode
- CVE-2022-47961 PoCIncorrect Use of Privileged APIs in usememos/memos
- CVE-2022-47971 PoCImproper Restriction of Excessive Authentication Attempts in usememos/memos
- CVE-2022-47981 PoCAuthorization Bypass Through User-Controlled Key in usememos/memos
- CVE-2022-47991 PoCAuthorization Bypass Through User-Controlled Key in usememos/memos
- CVE-2022-48001 PoCImproper Verification of Source of a Communication Channel in usememos/memos
- CVE-2022-48011 PoCInsufficient Granularity of Access Control in usememos/memos
- CVE-2022-48021 PoCAuthorization Bypass Through User-Controlled Key in usememos/memos
- CVE-2022-48031 PoCAuthorization Bypass Through User-Controlled Key in usememos/memos
- CVE-2022-48051 PoCIncorrect Use of Privileged APIs in usememos/memos
- CVE-2022-48061 PoCAuthorization Bypass Through User-Controlled Key in usememos/memos
- CVE-2022-48071 PoCImproper Access Control in usememos/memos
- CVE-2022-48081 PoCImproper Privilege Management in usememos/memos
- CVE-2022-48091 PoCImproper Access Control in usememos/memos
- CVE-2022-48101 PoCImproper Access Control in usememos/memos
- CVE-2022-48111 PoCAuthorization Bypass Through User-Controlled Key in usememos/memos
- CVE-2022-48121 PoCAuthorization Bypass Through User-Controlled Key in usememos/memos
- CVE-2022-48131 PoCInsufficient Granularity of Access Control in usememos/memos
- CVE-2022-48141 PoCImproper Access Control in usememos/memos
- CVE-2022-48241 PoCWP Blog and Widget < 2.3.1 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48251 PoCWP-ShowHide < 1.05 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48261 PoCSimple Tooltips < 2.1.4 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48271 PoCWP Tiles <= 1.1.2 - Contributor+ Stored XSS
- CVE-2022-48281 PoCBold Timeline Lite < 1.1.5 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48291 PoCShow-Hide / Collapse-Expand < 1.3.0 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48301 PoCPaid Memberships Pro < 2.9.9 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48311 PoCCustom User Profile Fields for User Registration & Member Frontend Profiles with Paid Memberships Pro < 1.8.1 - Contributor+ Stored XSS…
- CVE-2022-48321 PoCStore Locator WordPress < 1.4.9 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48331 PoCYourChannel: Everything you want in a YouTube plugin < 1.2.3 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48341 PoCCPT Bootstrap Carousel <= 1.12 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48351 PoCSocial Sharing Toolkit <= 2.6 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48361 PoCBreadcrumb < 1.5.33 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48371 PoCCPO Companion < 1.1.0 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48381 PoCClean Login < 1.13.7 - Contributor+ Stored XSS via Shortcode
- CVE-2022-48391 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2022-48401 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2022-48411 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2022-48431 PoCNULL Pointer Dereference in radareorg/radare2
- CVE-2022-48441 PoCCross-Site Request Forgery (CSRF) in usememos/memos
- CVE-2022-48451 PoCCross-Site Request Forgery (CSRF) in usememos/memos
- CVE-2022-48461 PoCCross-Site Request Forgery (CSRF) in usememos/memos
- CVE-2022-48471 PoCIncorrectly Specified Destination in a Communication Channel in usememos/memos
- CVE-2022-48481 PoCImproper Verification of Source of a Communication Channel in usememos/memos
- CVE-2022-48491 PoCCross-Site Request Forgery (CSRF) in usememos/memos
- CVE-2022-48501 PoCCross-Site Request Forgery (CSRF) in usememos/memos
- CVE-2022-48511 PoCImproper Handling of Values in usememos/memos
- CVE-2022-48551 PoCSourceCodester Lead Management System login.php sql injection
- CVE-2022-48561 PoCModbus Tools Modbus Slave mbs File mbslave.exe buffer overflow
- CVE-2022-48571 PoCModbus Tools Modbus Poll mbp File mbpoll.exe buffer overflow
- CVE-2022-48631 PoCImproper Handling of Insufficient Permissions or Privileges in usememos/memos
- CVE-2022-48641 PoCArgument Injection in froxlor/froxlor
- CVE-2022-48651 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2022-48661 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2022-48671 PoCCross-Site Request Forgery (CSRF) in froxlor/froxlor
- CVE-2022-48681 PoCImproper Authorization in froxlor/froxlor
- CVE-2022-48721 PoCWooCommerce Chained Products < 2.12.0 - Unauthenticated Arbitrary Options Update to 'no'
- CVE-2022-48821 PoCkaltura mwEmbed Share Plugin share.js cross site scripting
- CVE-2022-48881 PoCMultiple Plugins from Addify - Multiple CSRF
- CVE-2022-48911 PoCSisimai string.rb to_plain redos
- CVE-2022-48961 PoCCyber Control, in its 1.650 version, is affected by a vulnerability in the generation on the server of pop-up windows with the messages…
- CVE-2022-48972 PoCsBackupBuddy < 8.8.3 - Multiple Reflected Cross-Site Scripting
- CVE-2022-49391 PoCWCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation
- CVE-2022-49401 PoCWCFM Membership <= 2.10.0 - Missing Authorization
- CVE-2022-49444 PoCskalcaddle KodExplorer cross-site request forgery
- CVE-2022-49461 PoCFrontend Post WordPress Plugin <= 2.8.4 - Contributor+ Arbitrary Redirect
- CVE-2022-49533 PoCsElementor < 3.5.5 - Iframe Injection
- CVE-2022-49561 PoCCaphyon Advanced Installer WinSxS DLL uncontrolled search path
- CVE-2022-49581 PoCqkmc-rk redbbs Post cross site scripting
- CVE-2022-49591 PoCqkmc-rk redbbs Nickname cross site scripting
- CVE-2022-49601 PoCcloudfavorites favorites-web Nickname cross site scripting
- CVE-2022-49621 PoCApollo Configuration Center users improper authorization
- CVE-2022-49641 PoCUbuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.
- CVE-2022-49712 PoCsSassy Social Share <= 3.3.3 - Reflected Cross-Site Scripting
- CVE-2022-49731 PoCWordPress Core < 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function
- CVE-2022-49782 PoCsSteppschuh Remote Control Server 3.1.1.12 Unauthenticated RCE
- CVE-2022-49811 PoCDCMTK dcmqrscp dcmqrcnf.cc readPeerList null pointer dereference
- CVE-2022-49822 PoCsDBLTek GoIP-1 vGHSFVT-1.1-67-5 Unauthenticated LFI
- CVE-2022-49852 PoCsVodafone H500s WiFi Password Disclosure via activation.json
- CVE-2022-49952 PoCsWeaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp
- CVE-2022-49961 PoCmruby bigint.c udiv floating point comparison with incorrect operator