CVE Database

CVE-2022-3214CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to  1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer authorization, allowing remote code execution.

CVE-2022-35939CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TensorFlow is an open source platform for machine learning. The `ScatterNd` function takes an input argument that determines the indices of of the output tensor. An input index greater than the output tensor or less than zero will either write content at the wrong index or trigger a crash. We have patched the issue in GitHub commit b4d4b4cb019bd7240a52daa4ba61e3cc814f0384. The fix will be included in TensorFlow 2.10.0. We will also cherrypick this commit on TensorFlow 2.9.1, TensorFlow 2.8.1, and TensorFlow 2.7.2, as these are also affected and still in supported range. There are no known workarounds for this issue.

CVE-2022-37258CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.

CVE-2022-40300CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.

CVE-2022-39217CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security API and shoves it into a CSV. In affected versions this GitHub Action creates a CSV file without sanitizing the output of the APIs. If an alert is dismissed or any other custom field contains executable code / formulas, it might be run when an endpoint opens that CSV file in a spreadsheet program. This issue has been addressed in version `v1`. Users are advised to use `v1` or later. There are no known workarounds for this issue.

CVE-2022-40766CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring.

CVE-2022-2754CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks

CVE-2022-38880CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The affected version is 0.1.0.

CVE-2022-40424CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-networking package. The affected version of d8s-urls is 0.1.0

CVE-2022-40427CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0

CVE-2022-40805CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-urls for python 0.1.0, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-hypothesis package.

CVE-2022-40806CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-uuids for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

CVE-2022-40807CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

CVE-2022-40808CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

CVE-2022-40811CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

CVE-2022-37203CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-38881CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

CVE-2022-38882CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

CVE-2022-38883CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

CVE-2022-38884CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

CVE-2022-38885CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

CVE-2022-38886CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

CVE-2022-38887CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0.

CVE-2022-40425CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-html for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

CVE-2022-40426CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-asns for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

CVE-2022-40428CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-mpeg for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

CVE-2022-40429CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

CVE-2022-40430CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-utility for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

CVE-2022-40431CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

CVE-2022-40432CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.

CVE-2022-40809CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-dicts for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

CVE-2022-40810CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

CVE-2022-40812CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

CVE-2022-3218CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-603

Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.

CVE-2022-40144CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations.

CVE-2022-23767CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing remote code, thereby taking over the victim’s system.

CVE-2022-23768CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device.

CVE-2022-0143CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-284

When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)

CVE-2022-28321CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with denied access to a machine can still get access. NOTE: the relevance of this issue is largely limited to openSUSE Tumbleweed and openSUSE Factory; it does not affect Linux-PAM upstream.

CVE-2022-38509CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.

CVE-2022-39955CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited by declaring multiple Content-Type "charset" names and therefore bypassing the configurable CRS Content-Type header "charset" allow list. An encoded payload can bypass CRS detection this way and may then be decoded by the backend. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised to upgrade to 3.2.2 and 3.3.3 respectively.

CVE-2022-39956CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set. The multipart payload will therefore bypass detection. A vulnerable backend that supports these encoding schemes can potentially be exploited. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised upgrade to 3.2.2 and 3.3.3 respectively. The mitigation against these vulnerabilities depends on the installation of the latest ModSecurity version (v2.9.6 / v3.0.8).

CVE-2022-37204CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Final CMS 5.1.0 is vulnerable to SQL Injection.

CVE-2022-38916CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files

CVE-2017-20148CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls.

CVE-2022-37265CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.

CVE-2022-41138CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.

CVE-2022-40008CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.

CVE-2022-32788CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. A remote user may be able to cause kernel code execution.

CVE-2022-32863CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. Processing maliciously crafted web content may lead to arbitrary code execution.

← PreviousPage 450 / 7034Next →