Total
34640 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-34500 | 1 Pypi | 1 Pypi | 2024-11-21 | N/A | 9.8 CRITICAL |
|
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
|
|||||
| CVE-2022-34432 | 1 Dell | 1 Hybrid Client | 2024-11-21 | N/A | 7.3 HIGH |
|
Dell Hybrid Client below 1.8 version contains a gedit vulnerability. A guest attacker could potentially exploit this vulnerability, allowing deletion of user and some system files and folders.
|
|||||
| CVE-2022-34391 | 1 Dell | 4 Alienware Area-51 R4, Alienware Area-51 R4 Firmware, Alienware Area-51 R5 and 1 more | 2024-11-21 | N/A | 7.5 HIGH |
|
Dell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
|
|||||
| CVE-2022-34382 | 1 Dell | 3 Alienware Update, Command Update, Update | 2024-11-21 | N/A | 7.8 HIGH |
|
Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges.
|
|||||
| CVE-2022-34356 | 1 Ibm | 2 Aix, Vios | 2024-11-21 | N/A | 7.8 HIGH |
|
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to obtain root privileges. IBM X-Force ID: 230502.
|
|||||
| CVE-2022-34355 | 1 Ibm | 2 Collaborative Lifecycle Management, Engineering Lifecycle Management | 2024-11-21 | N/A | 4.0 MEDIUM |
|
IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a user that could be used in further attacks against the system. IBM X-Force ID: 230498.
|
|||||
| CVE-2022-34329 | 1 Ibm | 1 Cics Tx | 2024-11-21 | N/A | 5.3 MEDIUM |
|
IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 229467.
|
|||||
| CVE-2022-34303 | 3 Eurosoft-uk, Microsoft, Redhat | 10 Uefi Bootloader, Windows 10, Windows 11 and 7 more | 2024-11-21 | N/A | 6.7 MEDIUM |
|
A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
|
|||||
| CVE-2022-34302 | 3 Horizondatasys, Microsoft, Redhat | 10 Uefi Bootloader, Windows 10, Windows 11 and 7 more | 2024-11-21 | N/A | 6.7 MEDIUM |
|
A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
|
|||||
| CVE-2022-34301 | 3 Kidan, Microsoft, Redhat | 10 Cryptopro Securedisk For Bitlocker, Windows 10, Windows 11 and 7 more | 2024-11-21 | N/A | 6.7 MEDIUM |
|
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
|
|||||
| CVE-2022-34296 | 1 Zalando | 1 Skipper | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.
|
|||||
| CVE-2022-34293 | 1 Wolfssl | 1 Wolfssl | 2024-11-21 | N/A | 7.5 HIGH |
|
wolfSSL before 5.4.0 allows remote attackers to cause a denial of service via DTLS because a check for return-routability can be skipped.
|
|||||
| CVE-2022-34181 | 1 Jenkins | 1 Xunit | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
|
Jenkins xUnit Plugin 3.0.8 and earlier implements an agent-to-controller message that creates a user-specified directory if it doesn't exist, and parsing files inside it as test results, allowing attackers able to control agent processes to create an arbitrary directory on the Jenkins controller or to obtain test results from existing files in an attacker-specified directory.
|
|||||
| CVE-2022-34147 | 1 Intel | 82 Cm8ccb4r, Cm8ccb4r Firmware, Cm8i3cb4n and 79 more | 2024-11-21 | N/A | 7.5 HIGH |
|
Improper input validation in BIOS firmware for some Intel(R) NUC 9 Extreme Laptop Kits, Intel(R) NUC Performance Kits, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 Compute Element, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board, and Intel(R) NUC Compute Element may allow a privileged user to potentially enable escalation of privilege via local access.
|
|||||
| CVE-2022-34113 | 1 Dataease | 1 Dataease | 2024-11-21 | N/A | 9.8 CRITICAL |
|
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
|
|||||
| CVE-2022-34110 | 1 Msi | 1 Micro-star International Feature Navigator | 2024-11-21 | N/A | 5.5 MEDIUM |
|
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file type or size.
|
|||||
| CVE-2022-34109 | 1 Msi | 1 Micro-star International Feature Navigator | 2024-11-21 | N/A | 7.1 HIGH |
|
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPhoto\, regardless of file type or size.
|
|||||
| CVE-2022-34108 | 1 Msi | 1 Micro-star International Feature Navigator | 2024-11-21 | N/A | 7.1 HIGH |
|
An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Service (DoS) via a crafted image or video file.
|
|||||
| CVE-2022-34100 | 1 Crestron | 1 Airmedia | 2024-11-21 | N/A | 8.8 HIGH |
|
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installation of a trusted service executable and change permissions on that file structure during a repair operation.
|
|||||
| CVE-2022-34056 | 1 Pypi | 1 Watertools | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
|
|||||
| CVE-2022-34055 | 1 Pypi | 1 Drxhello | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
|
|||||
| CVE-2022-34054 | 1 Pypi | 1 Perdido | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
|
|||||
| CVE-2022-34053 | 1 Pypi | 1 Dr-web-engine | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
|
|||||
| CVE-2022-34032 | 1 F5 | 1 Njs | 2024-11-21 | N/A | 7.5 HIGH |
|
Nginx NJS v0.7.5 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.
|
|||||
| CVE-2022-34031 | 1 F5 | 1 Njs | 2024-11-21 | N/A | 7.5 HIGH |
|
Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_value_to_number at src/njs_value_conversion.h.
|
|||||
| CVE-2022-34030 | 1 F5 | 1 Njs | 2024-11-21 | N/A | 7.5 HIGH |
|
Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_djb_hash at src/njs_djb_hash.c.
|
|||||
| CVE-2022-34028 | 1 F5 | 1 Njs | 2024-11-21 | N/A | 7.5 HIGH |
|
Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h.
|
|||||
| CVE-2022-34027 | 1 F5 | 1 Njs | 2024-11-21 | N/A | 7.5 HIGH |
|
Nginx NJS v0.7.4 was discovered to contain a segmentation violation via njs_value_property at njs_value.c.
|
|||||
| CVE-2022-33993 | 1 Domain Name Relay Daemon Project | 1 Domain Name Relay Daemon | 2024-11-21 | N/A | 5.3 MEDIUM |
|
Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.
|
|||||
| CVE-2022-33992 | 1 Domain Name Relay Daemon Project | 1 Domain Name Relay Daemon | 2024-11-21 | N/A | 7.5 HIGH |
|
DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.
|
|||||
| CVE-2022-33987 | 1 Got Project | 1 Got | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
|
|||||
| CVE-2022-33980 | 3 Apache, Debian, Netapp | 3 Commons Configuration, Debian Linux, Snapcenter | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote serv ...
Show More |
|||||
| CVE-2022-33959 | 1 Ibm | 1 Sterling Order Management | 2024-11-21 | N/A | 5.4 MEDIUM |
|
IBM Sterling Order Management 10.0 could allow a user to bypass validation and perform unauthorized actions on behalf of other users. IBM X-Force ID: 229320.
|
|||||
| CVE-2022-33945 | 1 Intel | 66 Compute Module Hns2600bpb, Compute Module Hns2600bpb24, Compute Module Hns2600bpb24 Firmware and 63 more | 2024-11-21 | N/A | 8.2 HIGH |
|
Improper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
|
|||||
| CVE-2022-33939 | 1 Yokogawa | 14 Centum Cs 3000 Cp31, Centum Cs 3000 Cp31 Firmware, Centum Cs 3000 Cp33 and 11 more | 2024-11-21 | N/A | 7.5 HIGH |
|
CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451) contains an issue in processing communication packets, which may lead to resource consumption. If this vulnerability is exploited, an attacker may cause a denial of service (DoS) condition in ADL communication by sending a specially crafted packet to the affected product.
|
|||||
| CVE-2022-33936 | 1 Dell | 1 Cloud Mobility For Dell Emc Storage | 2024-11-21 | 10.0 HIGH | 8.0 HIGH |
|
Cloud Mobility for Dell EMC Storage, 1.3.0.XXX contains a RCE vulnerability. A non-privileged user could potentially exploit this vulnerability, leading to achieving a root shell. This is a critical issue; so Dell recommends customers to upgrade at the earliest opportunity.
|
|||||
| CVE-2022-33917 | 1 Arm | 1 Valhall Gpu Kernel Driver | 2024-11-21 | N/A | 5.5 MEDIUM |
|
An issue was discovered in the Arm Mali GPU Kernel Driver (Valhall r29p0 through r38p0). A non-privileged user can make improper GPU processing operations to gain access to already freed memory.
|
|||||
| CVE-2022-33916 | 1 Opcfoundation | 1 Ua .net Standard Stack | 2024-11-21 | N/A | 7.5 HIGH |
|
OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.
|
|||||
| CVE-2022-33903 | 1 Torproject | 1 Tor | 2024-11-21 | N/A | 7.5 HIGH |
|
Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
|
|||||
| CVE-2022-33894 | 1 Intel | 546 Core I3-1000g1, Core I3-1000g1 Firmware, Core I3-1000g4 and 543 more | 2024-11-21 | N/A | 7.5 HIGH |
|
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
|
|||||