CVE-2022-50000 to CVE-2022-50999
115 CVEs with public proof-of-concept exploits.
- CVE-2022-506871 PoCCobian Backup 11 Gravity 11.2.0.582 Local Denial of Service via Password Field
- CVE-2022-506881 PoCCobian Backup Gravity 11.2.0.582 Unquoted Service Path Privilege Escalation
- CVE-2022-506891 PoCCobian Reflector 0.9.93 RC1 Local Denial of Service via Password Field
- CVE-2022-506901 PoCWondershare MirrorGo 2.0.11.346 Local Privilege Escalation via Insecure File Permissions
- CVE-2022-506911 PoCMiniDVBLinux 5.4 Remote Root Command Execution via commands.sh
- CVE-2022-506921 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient Session Expiration Vulnerability
- CVE-2022-506931 PoCSplashtop 8.71.12001.0 - Unquoted Service Path
- CVE-2022-506941 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x SQL Injection via Username Parameter
- CVE-2022-506951 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack via Network Commands
- CVE-2022-506961 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication Bypass
- CVE-2022-507871 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Stored Cross-Site Scripting
- CVE-2022-507881 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory
- CVE-2022-507891 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via dns.php
- CVE-2022-507901 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Radio Stream Disclosure
- CVE-2022-507911 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via ping.php
- CVE-2022-507921 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability
- CVE-2022-507931 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php
- CVE-2022-507941 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via Username
- CVE-2022-507951 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via traceroute.php
- CVE-2022-507961 PoCSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Remote Code Execution via upload.cgi
- CVE-2022-507971 PoCStripe Green Downloads Wordpress Plugin 2.03 Persistent XSS via Settings
- CVE-2022-507991 PoCFetch Softworks Fetch FTP Client 5.8.2 Remote CPU Consumption Denial of Service
- CVE-2022-508001 PoCH3C SSL VPN n/a Username Enumeration via Login Script Credential Verification
- CVE-2022-508011 PoCJM-DATA ONU JF511-TV 1.0.67 Authenticated Stored Cross-Site Scripting (XSS) Vulnerability
- CVE-2022-508021 PoCETAP Safety Manager 1.0.0.32 Unauthenticated Reflected Cross-Site Scripting via Action Parameter
- CVE-2022-508031 PoCJM-DATA ONU JF511-TV 1.0.67 Default Credentials Vulnerability
- CVE-2022-508041 PoCJM-DATA ONU JF511-TV 1.0.67 Cross-Site Request Forgery (CSRF) Vulnerability
- CVE-2022-508051 PoCSenayan Library Management System 9.0.0 - SQL Injection
- CVE-2022-508061 PoC4images 1.9 - Remote Command Execution (RCE)
- CVE-2022-508081 PoCCoolerMaster MasterPlus 1.8.5 - 'MPService' Unquoted Service Path
- CVE-2022-508902 PoCsOwlfiles File Manager 12.0.1 - Path Traversal
- CVE-2022-508911 PoCOwlfiles File Manager 12.0.1 Cross-Site Scripting via HTTP Server
- CVE-2022-508921 PoCVIAVIWEB Wallpaper Admin 1.0 - SQL Injection via Login Page
- CVE-2022-508931 PoCVIAVIWEB Wallpaper Admin 1.0 - Code Execution via Image Upload
- CVE-2022-508941 PoCVIAVIWEB Wallpaper Admin 1.0 SQL Injection via edit_gallery_image.php
- CVE-2022-508951 PoCAero CMS 0.0.1 - SQL Injection
- CVE-2022-508961 PoCTesta 3.5.1 Online Test Management System - Reflected Cross-Site Scripting (XSS)
- CVE-2022-508971 PoCmPDF 7.0 - Local File Inclusion
- CVE-2022-508982 PoCsNanoCMS 0.4 - Remote Code Execution (RCE) (Authenticated)
- CVE-2022-508991 PoCGeonetwork 4.2.0 - XML External Entity (XXE)
- CVE-2022-509001 PoCWondershare Dr.Fone 12.0.18 - 'Wondershare InstallAssist' Unquoted Service Path
- CVE-2022-509011 PoCWondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Path
- CVE-2022-509021 PoCWondershare FamiSafe 1.0 - 'FSService' Unquoted Service Path
- CVE-2022-509031 PoCWondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service Path
- CVE-2022-509041 PoCWondershare UBackit 2.0.5 - 'wsbackup' Unquoted Service Path
- CVE-2022-509051 PoCe107 CMS v3.2.1 - Reflected XSS via Comment Flow
- CVE-2022-509061 PoCe107 CMS v3.2.1 - Admin Upload Restriction Bypass + Stored XSS
- CVE-2022-509071 PoCe107 CMS v3.2.1 - Admin Upload Restriction Bypass + RCE
- CVE-2022-509081 PoCMailhog 1.0.1 - Stored Cross-Site Scripting (XSS)
- CVE-2022-509091 PoCAlgo 8028 Control Panel - Remote Code Execution (RCE) (Authenticated)
- CVE-2022-509102 PoCsBeehive Forum - Account Takeover
- CVE-2022-509121 PoCImpressCMS 1.4.4 - Unrestricted File Upload
- CVE-2022-509131 PoCTCQ - 'ITeCProteccioAppServer.exe' Unquoted Service Path
- CVE-2022-509141 PoCEaseUS Data Recovery - 'ensserver.exe' Unquoted Service Path
- CVE-2022-509151 PoCPTPublisher 2.3.4 - Unquoted Service Path
- CVE-2022-509161 PoCe107 CMS v3.2.1 - Upload restriction bypass (Authenticated [Admin])+ Server file override
- CVE-2022-509171 PoCProtonVPN 1.26.0 - Unquoted Service Path
- CVE-2022-509181 PoCVIVE Runtime Service - 'ViveAgentService' Unquoted Service Path
- CVE-2022-509191 PoCTdarr 2.00.15 - Command Injection
- CVE-2022-509201 PoCSandboxie-Plus 5.50.2 - 'Service SbieSvc' Unquoted Service Path
- CVE-2022-509211 PoCWOW21 5.0.1.9 - 'Service WOW21_Service' Unquoted Service Path
- CVE-2022-509221 PoCAudio Conversion Wizard v2.01 - Buffer Overflow
- CVE-2022-509231 PoCCobian Backup 0.9 - Unquoted Service Path
- CVE-2022-509241 PoCPrivate Internet Access 3.3 - 'pia-service' Unquoted Service Path
- CVE-2022-509251 PoCProwise Reflect v1.0.9 - Remote Keystroke Injection
- CVE-2022-509261 PoCWAGO 750-8212 PFC200 G2 2ETH RS Privilege Escalation
- CVE-2022-509271 PoCCyclades Serial Console Server 3.3.0 - Local Privilege Escalation
- CVE-2022-509281 PoCBluetooth Application 5.4.277 - 'BlueSoleilCS' Unquoted Service Path
- CVE-2022-509291 PoCConnectify Hotspot 2018 'ConnectifyService' - Unquoted Service Path
- CVE-2022-509301 PoCEmerson PAC Machine Edition 9.80 Build 8695 - 'TrapiServer' Unquoted Service Path
- CVE-2022-509311 PoCTeamSpeak 3.5.6 - Insecure File Permissions
- CVE-2022-509321 PoCKyocera Command Center RX ECOSYS M2035dn - Directory Traversal File Disclosure (Unauthenticated)
- CVE-2022-509331 PoCCain & Abel 4.9.56 - Unquoted Service Path
- CVE-2022-509351 PoCFLAME II MODEM USB - Unquoted Service Path
- CVE-2022-509361 PoCWBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)
- CVE-2022-509371 PoCAmetys CMS v4.4.1 - Cross Site Scripting (XSS)
- CVE-2022-509381 PoCCONTPAQi® AdminPAQ 14.0.0 - Unquoted Service Path
- CVE-2022-509391 PoCe107 CMS v3.2.1 - Upload Restriction Bypass with Path Traversal File Override
- CVE-2022-509401 PoCKnap Advanced PHP Login 3.1.3 Persistent Cross-Site Scripting via Name Parameter
- CVE-2022-509411 PoCBootCommerce 3.2.1 Persistent Cross-Site Scripting via Order Checkout
- CVE-2022-509421 PoCIncinga Web 2.8.2 Client-Side Cross-Site Scripting via EventListener
- CVE-2022-509431 PoCMoodle LMS 4.0 Cross-Site Scripting via course search.php
- CVE-2022-509441 PoCAero CMS 0.0.1 PHP Code Injection via posts.php
- CVE-2022-509451 PoCWordPress 3dady Real-Time Web Stats 1.0 Stored XSS
- CVE-2022-509461 PoCWordPress Plugin Netroics Blog Posts Grid 1.0 Stored XSS
- CVE-2022-509471 PoCWordPress Plugin Testimonial Slider and Showcase 2.2.6 Stored XSS
- CVE-2022-509481 PoCMotopress Hotel Booking Lite 4.2.4 Stored Cross-Site Scripting
- CVE-2022-509491 PoCWordPress Plugin Videos sync PDF 1.7.4 Stored XSS
- CVE-2022-509501 PoCWebile 1.0.1 Directory Traversal Vulnerability via Web Application
- CVE-2022-509511 PoCWiFi File Transfer 1.0.8 Persistent XSS via Web Server Input Validation
- CVE-2022-509521 PoCBanco Guayaquil 8.0.0 Mobile iOS Cross-Site Scripting via Profile Name Input
- CVE-2022-509531 PoCWordPress Plugin admin-word-count-column 2.2 Local File Read
- CVE-2022-509541 PoCWordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion
- CVE-2022-509551 PoCWordPress Plugin Curtain 1.0.2 Cross-site Request Forgery
- CVE-2022-509561 PoCWordPress Plugin amministrazione-aperta 3.7.3 Local File Read
- CVE-2022-509571 PoCDrupal avatar_uploader 7.x-1.0-beta8 Reflected XSS
- CVE-2022-509581 PoCWordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php
- CVE-2022-509591 PoCWordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php
- CVE-2022-509601 PoCWordPress International Sms Contact Form 7 Integration 1.2 XSS
- CVE-2022-509611 PoCWordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSS
- CVE-2022-509622 PoCsuBidAuction 2.0.1 myOrders Reflected XSS
- CVE-2022-509632 PoCsuBidAuction 2.0.1 myAuctions active Reflected XSS
- CVE-2022-509642 PoCsuBidAuction 2.0.1 myAuctions loose Reflected XSS
- CVE-2022-509652 PoCsuBidAuction 2.0.1 posts manage Reflected XSS
- CVE-2022-509662 PoCsuBidAuction 2.0.1 news manage Reflected XSS
- CVE-2022-509672 PoCsuBidAuction 2.0.1 tickets manage Reflected XSS
- CVE-2022-509682 PoCsuBidAuction 2.0.1 auctions manage Reflected XSS
- CVE-2022-509692 PoCsuBidAuction 2.0.1 mailingLog manage Reflected XSS
- CVE-2022-509701 PoCWordPress Plugin AAWP 3.16 Reflected XSS via tab Parameter
- CVE-2022-509711 PoCMalwarebytes 4.5 Unquoted Service Path Privilege Escalation
- CVE-2022-509721 PoCWooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
- CVE-2022-509733 PoCsYonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet
- CVE-2022-509922 PoCsWeaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet
- CVE-2022-509932 PoCsWeaver E-office < 10.0_20221201 Unauthenticated Arbitrary File Read via XmlRpcServlet
- CVE-2022-509971 PoCWeaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp