Latest CVE Feed
-
9.8
CRITICALCVE-2022-34598
The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands.... Read more
- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34440
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to th... Read more
- Published: Jan. 11, 2023
- Modified: May. 20, 2025
-
9.8
CRITICALCVE-2022-34442
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to ... Read more
Affected Products : emc_secure_connect_gateway_policy_manager policy_manager_for_secure_connect_gateway- Published: Jan. 18, 2023
- Modified: May. 20, 2025
-
9.8
CRITICALCVE-2022-34599
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm.... Read more
- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34372
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker... Read more
Affected Products : powerprotect_cyber_recovery- Published: Sep. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34371
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotected transport of credentials vulnerability. A malicious unprivileged network attacker could potentially exploit this vulnerability, lead... Read more
- Published: Sep. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34331
After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695.... Read more
Affected Products : powervm_hypervisor- Published: Nov. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34270
An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.... Read more
Affected Products : worldserver- Published: Feb. 29, 2024
- Modified: Apr. 16, 2025
-
9.8
CRITICALCVE-2022-34267
An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpo... Read more
Affected Products : worldserver- Published: Dec. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34256
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other... Read more
- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34265
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind... Read more
Affected Products : django- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34060
The Togglee package in PyPI version v0.0.8 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : togglee- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34064
The Zibal package in PyPI v1.0.0 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : zibal- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34066
The Texercise package in PyPI v0.0.1 to v0.0.12 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : texercise- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34055
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : drxhello- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34294
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.... Read more
Affected Products : totd- Published: Aug. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34005
An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation... Read more
Affected Products : titan_ftp_server_nextgen- Published: Jun. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33980
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.confi... Read more
- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33754
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.... Read more
Affected Products : ca_automic_automation- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33880
hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.... Read more
Affected Products : hospital_management_system_mini-project- Published: Sep. 29, 2022
- Modified: May. 20, 2025