Total
3006 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-44276 | 1 Tecrail | 1 Responsive Filemanager | 2024-11-21 | N/A | 9.8 CRITICAL |
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE. | |||||
CVE-2022-44054 | 1 Democritus | 1 D8s-xml | 2024-11-21 | N/A | 9.8 CRITICAL |
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-utility package. The affected version of d8s-htm is 0.1.0. | |||||
CVE-2022-44053 | 1 Democritus | 1 D8s-networking | 2024-11-21 | N/A | 9.8 CRITICAL |
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents package. The affected version of d8s-htm is 0.1.0. | |||||
CVE-2022-44052 | 1 Democritus | 1 D8s-dates | 2024-11-21 | N/A | 9.8 CRITICAL |
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-timezones package. The affected version of d8s-htm is 0.1.0. | |||||
CVE-2022-44051 | 1 Democritus | 1 D8s-stats | 2024-11-21 | N/A | 9.8 CRITICAL |
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.0. | |||||
CVE-2022-44050 | 1 Democritus | 1 D8s-networking | 2024-11-21 | N/A | 9.8 CRITICAL |
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-json package. The affected version of d8s-htm is 0.1.0. | |||||
CVE-2022-44049 | 1 Democritus | 1 D8s-python | 2024-11-21 | N/A | 9.8 CRITICAL |
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-grammars package. The affected version of d8s-htm is 0.1.0. | |||||
CVE-2022-44048 | 1 Democritus | 1 D8s-urls | 2024-11-21 | N/A | 9.8 CRITICAL |
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version of d8s-htm is 0.1.0. | |||||
CVE-2022-44036 | 1 B2evolution | 1 B2evolution Cms | 2024-11-21 | N/A | 7.2 HIGH |
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it." | |||||
CVE-2022-43979 | 1 Pandorafms | 1 Pandora Fms | 2024-11-21 | N/A | 5.9 MEDIUM |
There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user has inserted does not contain malicious characteres, but this check is insufficient. An attacker could insert an absolute path to overcome the heck, thus being able to incluse any PHP file that resides on the disk. The exploitation of this vulnerability could lead to a remote code execution. | |||||
CVE-2022-43436 | 1 Easy Test Project | 1 Easy Test | 2024-11-21 | N/A | 8.8 HIGH |
The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general user can upload and execute arbitrary files, to manipulate system or disrupt service. | |||||
CVE-2022-43306 | 1 Democritus | 1 D8s-timer | 2024-11-21 | N/A | 8.8 HIGH |
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-dates package. The affected version of d8s-htm is 0.1.0. | |||||
CVE-2022-43305 | 1 Democritus | 1 D8s-python | 2024-11-21 | N/A | 9.8 CRITICAL |
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-algorithms package. The affected version of d8s-htm is 0.1.0. | |||||
CVE-2022-43304 | 1 Democritus | 1 D8s-timer | 2024-11-21 | N/A | 9.8 CRITICAL |
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version of d8s-htm is 0.1.0. | |||||
CVE-2022-43303 | 1 Democritus | 1 D8s-strings | 2024-11-21 | N/A | 9.8 CRITICAL |
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version of d8s-htm is 0.1.0. | |||||
CVE-2022-43283 | 1 Webassembly | 1 Wabt | 2024-11-21 | N/A | 5.5 MEDIUM |
wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write. | |||||
CVE-2022-43277 | 1 Canteen Management System Project | 1 Canteen Management System | 2024-11-21 | N/A | 7.2 HIGH |
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_action/editFile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-43275 | 1 Canteen Management System Project | 1 Canteen Management System | 2024-11-21 | N/A | 7.2 HIGH |
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-43265 | 1 Canteen Management System Project | 1 Canteen Management System | 2024-11-21 | N/A | 9.8 CRITICAL |
An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-43234 | 1 Hoosk | 1 Hoosk | 2024-11-21 | N/A | 9.8 CRITICAL |
An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file. |