Total
32703 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-34329 | 1 Ibm | 1 Cics Tx | 2024-11-21 | N/A | 5.3 MEDIUM |
IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 229467. | |||||
CVE-2022-34303 | 3 Eurosoft-uk, Microsoft, Redhat | 10 Uefi Bootloader, Windows 10, Windows 11 and 7 more | 2024-11-21 | N/A | 6.7 MEDIUM |
A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media. | |||||
CVE-2022-34302 | 3 Horizondatasys, Microsoft, Redhat | 10 Uefi Bootloader, Windows 10, Windows 11 and 7 more | 2024-11-21 | N/A | 6.7 MEDIUM |
A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media. | |||||
CVE-2022-34301 | 3 Kidan, Microsoft, Redhat | 10 Cryptopro Securedisk For Bitlocker, Windows 10, Windows 11 and 7 more | 2024-11-21 | N/A | 6.7 MEDIUM |
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media. | |||||
CVE-2022-34296 | 1 Zalando | 1 Skipper | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request. | |||||
CVE-2022-34293 | 1 Wolfssl | 1 Wolfssl | 2024-11-21 | N/A | 7.5 HIGH |
wolfSSL before 5.4.0 allows remote attackers to cause a denial of service via DTLS because a check for return-routability can be skipped. | |||||
CVE-2022-34181 | 1 Jenkins | 1 Xunit | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
Jenkins xUnit Plugin 3.0.8 and earlier implements an agent-to-controller message that creates a user-specified directory if it doesn't exist, and parsing files inside it as test results, allowing attackers able to control agent processes to create an arbitrary directory on the Jenkins controller or to obtain test results from existing files in an attacker-specified directory. | |||||
CVE-2022-34147 | 1 Intel | 82 Cm8ccb4r, Cm8ccb4r Firmware, Cm8i3cb4n and 79 more | 2024-11-21 | N/A | 7.5 HIGH |
Improper input validation in BIOS firmware for some Intel(R) NUC 9 Extreme Laptop Kits, Intel(R) NUC Performance Kits, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 Compute Element, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board, and Intel(R) NUC Compute Element may allow a privileged user to potentially enable escalation of privilege via local access. | |||||
CVE-2022-34113 | 1 Dataease | 1 Dataease | 2024-11-21 | N/A | 9.8 CRITICAL |
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin. | |||||
CVE-2022-34110 | 1 Msi | 1 Micro-star International Feature Navigator | 2024-11-21 | N/A | 5.5 MEDIUM |
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file type or size. | |||||
CVE-2022-34109 | 1 Msi | 1 Micro-star International Feature Navigator | 2024-11-21 | N/A | 7.1 HIGH |
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPhoto\, regardless of file type or size. | |||||
CVE-2022-34108 | 1 Msi | 1 Micro-star International Feature Navigator | 2024-11-21 | N/A | 7.1 HIGH |
An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Service (DoS) via a crafted image or video file. | |||||
CVE-2022-34100 | 1 Crestron | 1 Airmedia | 2024-11-21 | N/A | 8.8 HIGH |
A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging a file structure prior to the installation of a trusted service executable and change permissions on that file structure during a repair operation. | |||||
CVE-2022-34056 | 1 Pypi | 1 Watertools | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |||||
CVE-2022-34055 | 1 Pypi | 1 Drxhello | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |||||
CVE-2022-34054 | 1 Pypi | 1 Perdido | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |||||
CVE-2022-34053 | 1 Pypi | 1 Dr-web-engine | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |||||
CVE-2022-34032 | 1 F5 | 1 Njs | 2024-11-21 | N/A | 7.5 HIGH |
Nginx NJS v0.7.5 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c. | |||||
CVE-2022-34031 | 1 F5 | 1 Njs | 2024-11-21 | N/A | 7.5 HIGH |
Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_value_to_number at src/njs_value_conversion.h. | |||||
CVE-2022-34030 | 1 F5 | 1 Njs | 2024-11-21 | N/A | 7.5 HIGH |
Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_djb_hash at src/njs_djb_hash.c. |