Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file. | https://github.com/p0dalirius/CVE-2022-26159-Ametys-Autocompletion-XML | POC Details |
| 2 | Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/domain/en.xml (and similar pathnames for other languages) via the auto-completion plugin, which contain all characters typed by all users, including the content of private pages. For example, a private page may contain usernames, e-mail addresses, and possibly passwords. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26159.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-25028 | Home Owners Collection Management System 跨站脚本漏洞 | |
| CVE-2020-22844 | Mikrotik RouterOS 安全漏洞 | |
| CVE-2020-22845 | Mikrotik RouterOS 安全漏洞 | |
| CVE-2022-25013 | Ice Hrm 跨站脚本漏洞 | |
| CVE-2022-25014 | Ice Hrm 跨站脚本漏洞 | |
| CVE-2022-25015 | Ice Hrm 跨站脚本漏洞 | |
| CVE-2021-45414 | Datarobot 代码注入漏洞 | |
| CVE-2022-23906 | CMS Made Simple 代码问题漏洞 | |
| CVE-2022-23907 | CMS Made Simple 跨站脚本漏洞 | |
| CVE-2022-26181 | Dropbox Lepton 缓冲区错误漏洞 | |
| CVE-2022-25407 | PHPGurukul Hospital Management System 跨站脚本漏洞 | |
| CVE-2022-25408 | HealthNode Hospital Management System 跨站脚本漏洞 | |
| CVE-2022-25409 | HealthNode Hospital Management System跨站脚本漏洞 | |
| CVE-2022-25410 | MaxSite CMS 跨站脚本漏洞 | |
| CVE-2022-25411 | MaxSite CMS 代码问题漏洞 | |
| CVE-2022-25412 | MaxSite CMS 路径遍历漏洞 | |
| CVE-2022-25413 | MaxSite CMS 跨站脚本漏洞 | |
| CVE-2022-24571 | Car Driving School Management System SQL注入漏洞 | |
| CVE-2022-25023 | AudioFile 缓冲区错误漏洞 | |
| CVE-2022-26315 | qrcp 路径遍历漏洞 |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet