Latest CVE Feed
-
9.8
CRITICALCVE-2022-34060
The Togglee package in PyPI version v0.0.8 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : togglee- EPSS Score: %0.42
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34064
The Zibal package in PyPI v1.0.0 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : zibal- EPSS Score: %1.02
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34066
The Texercise package in PyPI v0.0.1 to v0.0.12 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : texercise- EPSS Score: %0.70
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34055
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : drxhello- EPSS Score: %0.70
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34294
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.... Read more
Affected Products : totd- EPSS Score: %0.74
- Published: Aug. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34005
An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation... Read more
Affected Products : titan_ftp_server_nextgen- EPSS Score: %1.60
- Published: Jun. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33980
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.confi... Read more
- EPSS Score: %87.66
- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33754
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.... Read more
Affected Products : ca_automic_automation- EPSS Score: %1.71
- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33880
hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.... Read more
Affected Products : hospital_management_system_mini-project- EPSS Score: %0.08
- Published: Sep. 29, 2022
- Modified: May. 20, 2025
-
9.8
CRITICALCVE-2022-34056
The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : watertools- EPSS Score: %0.42
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33321
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Condit... Read more
- EPSS Score: %0.69
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-33874
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote... Read more
Affected Products : fortitester- EPSS Score: %1.60
- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33279
Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length.... Read more
Affected Products : qca6391_firmware wcd9385_firmware ar9380_firmware csr8811_firmware ipq4028_firmware ipq4029_firmware ipq5010_firmware ipq5028_firmware ipq6000_firmware ipq6010_firmware +138 more products- EPSS Score: %0.18
- Published: Feb. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33174
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_pa... Read more
Affected Products : basic_pdu_firmware pm_pdu_firmware piml_pdu_firmware smart_pim_firmware smart_pos_firmware smart_pom_firmware smart_poms_firmware basic_pdu pm_pdu piml_pdu +4 more products- EPSS Score: %81.72
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33107
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload.... Read more
Affected Products : thinkphp- EPSS Score: %24.57
- Published: Jun. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33150
An OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnera... Read more
- EPSS Score: %0.28
- Published: Oct. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33175
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active ses... Read more
Affected Products : basic_pdu_firmware pm_pdu_firmware piml_pdu_firmware smart_pim_firmware smart_pos_firmware smart_pom_firmware smart_poms_firmware basic_pdu pm_pdu piml_pdu +4 more products- EPSS Score: %0.53
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33318
Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows a remote unauthenticated attacker to execute an arbitrary malicious code by s... Read more
- EPSS Score: %7.34
- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33162
IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources, at the privilege level of a... Read more
- Published: Aug. 16, 2024
- Modified: Sep. 07, 2024
-
9.8
CRITICALCVE-2022-33002
The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : explore- EPSS Score: %0.70
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024