Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-35089 | 1 Swftools | 1 Swftools | 2022-09-22 | N/A | 5.5 MEDIUM |
SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf. | |||||
CVE-2022-35090 | 1 Swftools | 1 Swftools | 2022-09-22 | N/A | 5.5 MEDIUM |
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_memintrinsics.cpp:. | |||||
CVE-2022-38619 | 1 Bpcbt | 1 Smartvista Front-end | 2022-09-22 | N/A | 9.8 CRITICAL |
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf. | |||||
CVE-2022-34746 | 1 Zyxel | 20 Gs1900-10hp, Gs1900-10hp Firmware, Gs1900-16 and 17 more | 2022-09-22 | N/A | 5.9 MEDIUM |
An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxel GS1900 series firmware versions prior to V2.70. This vulnerability could allow an unauthenticated attacker to retrieve a private key by factoring the RSA modulus N in the certificate of the web administration interface. | |||||
CVE-2021-46834 | 1 Huawei | 2 Jad-al50, Jad-al50 Firmware | 2022-09-22 | N/A | 5.5 MEDIUM |
A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4). | |||||
CVE-2022-33735 | 1 Huawei | 2 Ws7200-10, Ws7200-10 Firmware | 2022-09-22 | N/A | 6.5 MEDIUM |
There is a password verification vulnerability in WS7200-10 11.0.2.13. Attackers on the LAN may use brute force cracking to obtain passwords, which may cause sensitive system information to be disclosed. | |||||
CVE-2022-37395 | 1 Huawei | 2 Cv81-wdm Fw, Cv81-wdm Fw Firmware | 2022-09-22 | N/A | 7.5 HIGH |
A Huawei device has an input verification vulnerability. Successful exploitation of this vulnerability may lead to DoS attacks.Affected product versions include:CV81-WDM FW versions 01.70.49.29.46. | |||||
CVE-2022-37205 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-21 | N/A | 8.8 HIGH |
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | |||||
CVE-2016-20015 | 1 Smokeping | 1 Smokeping | 2022-09-21 | N/A | 7.5 HIGH |
In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving /var/lib/smokeping and chown. | |||||
CVE-2022-3245 | 1 Microweber | 1 Microweber | 2022-09-21 | N/A | 6.1 MEDIUM |
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input. | |||||
CVE-2022-40428 | 1 D8s-mpeg Project | 1 D8s Mpeg | 2022-09-21 | N/A | 9.8 CRITICAL |
The d8s-mpeg for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | |||||
CVE-2022-40429 | 1 D8s-ip-addresses Project | 1 D8s-ip-addresses | 2022-09-21 | N/A | 9.8 CRITICAL |
The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | |||||
CVE-2022-40425 | 1 D8s-html Project | 1 D8s-html | 2022-09-21 | N/A | 9.8 CRITICAL |
The d8s-html for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | |||||
CVE-2022-40426 | 1 D8s-asns Project | 1 D8s-asns | 2022-09-21 | N/A | 9.8 CRITICAL |
The d8s-asns for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | |||||
CVE-2022-40809 | 1 Democritus Dicts Project | 1 Democritus Dicts | 2022-09-21 | N/A | 9.8 CRITICAL |
The d8s-dicts for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0 | |||||
CVE-2022-40430 | 1 D8s-utility Project | 1 D8s-utility | 2022-09-21 | N/A | 9.8 CRITICAL |
The d8s-utility for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | |||||
CVE-2022-40810 | 1 Democritus Ip Addresses Project | 1 Democritus Ip Addresses | 2022-09-21 | N/A | 9.8 CRITICAL |
The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0 | |||||
CVE-2022-40812 | 1 Democritus Pdfs Project | 1 Democritus Pdfs | 2022-09-21 | N/A | 9.8 CRITICAL |
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | |||||
CVE-2022-40978 | 1 Jetbrains | 1 Intellij Idea | 2022-09-21 | N/A | 7.8 HIGH |
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking | |||||
CVE-2022-38333 | 1 Openwrt | 1 Openwrt | 2022-09-21 | N/A | 7.5 HIGH |
Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request. |