| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29333 | Hig | 0.51 | 7.8 | 0.01 | May 24, 2022 | A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file. | ||
| CVE-2022-23050 | Hig | 0.47 | 7.2 | 0.05 | May 24, 2022 | ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality. | ||
| CVE-2022-22977 | Hig | 0.46 | 7.1 | 0.01 | May 24, 2022 | VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to a… | ||
| CVE-2021-42614 | Hig | 0.51 | 7.8 | 0.01 | May 24, 2022 | A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have unspecified other impact via a crafted text document. | ||
| CVE-2021-42613 | Hig | 0.51 | 7.8 | 0.01 | May 24, 2022 | A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document. | ||
| CVE-2021-42612 | Hig | 0.51 | 7.8 | 0.01 | May 24, 2022 | A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document. | ||
| CVE-2021-3717 | Hig | 0.51 | 7.8 | 0.00 | May 24, 2022 | A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This… | ||
| CVE-2021-32969 | Hig | 0.51 | 7.8 | 0.01 | May 24, 2022 | Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result in a system crash or allow an attacker to remotely execute arbitrary code. | ||
| CVE-2021-32965 | Hig | 0.51 | 7.8 | 0.01 | May 24, 2022 | Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code. | ||
| CVE-2021-32962 | Hig | 0.53 | 8.2 | 0.01 | May 24, 2022 | The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code. | ||
| CVE-2022-22495 | Hig | 0.57 | 8.8 | 0.02 | May 24, 2022 | IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941. | ||
| CVE-2022-29249 | Hig | 0.42 | 7.5 | 0.01 | May 24, 2022 | JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may be critical in a situation where the highest levels of… | ||
| CVE-2014-125001 | Hig | 0.53 | 8.1 | 0.04 | May 24, 2022 | A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions is possible. Firewalling or disabling the service is recommended. | ||
| CVE-2022-31261 | Hig | 0.49 | 7.5 | 0.01 | May 24, 2022 | An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback ID of the configured identity source. A… | ||
| CVE-2022-30843 | Hig | 0.57 | 8.8 | 0.01 | May 24, 2022 | Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id. | ||
| CVE-2022-29223 | Hig | 0.49 | 7.5 | 0.01 | May 24, 2022 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can cause a buffer overflow by providing the Azure RTOS USBX host stack a HUB descriptor with `bNbPorts` set to a value greater than `UX_MAX_TT` which defaults to… | ||
| CVE-2022-29221 | Hig | 0.51 | 8.8 | 0.05 | May 24, 2022 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully… | ||
| CVE-2022-29219 | Hig | 0.42 | 7.5 | 0.01 | May 24, 2022 | Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a possible consensus split given maliciously-crafted `AttesterSlashing` or `ProposerSlashing` being included on-chain. Because the developers represent `uint64`… | ||
| CVE-2022-29217 | Hig | 0.41 | 7.4 | 0.01 | May 24, 2022 | PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported.… | ||
| CVE-2022-1850 | — | Hig | 0.46 | 8.1 | 0.01 | May 24, 2022 | Path Traversal in GitHub repository filegator/filegator prior to 7.8.0. | |
| CVE-2022-30463 | Hig | 0.57 | 8.8 | 0.01 | May 24, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product. | ||
| CVE-2022-30459 | Hig | 0.57 | 8.8 | 0.01 | May 24, 2022 | ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=delete_response, id. | ||
| CVE-2021-42655 | Hig | 0.57 | 8.8 | 0.01 | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. | ||
| CVE-2022-26532 | Hig | 0.51 | 7.8 | 0.05 | May 24, 2022 | A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through… | ||
| CVE-2022-29309 | Hig | 0.49 | 7.5 | 0.01 | May 24, 2022 | mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery. | ||
| CVE-2022-29305 | — | Hig | 0.53 | 8.1 | 0.01 | May 24, 2022 | imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost. | |
| CVE-2022-29377 | Hig | 0.49 | 7.5 | 0.01 | May 24, 2022 | Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH. | ||
| CVE-2022-29376 | Hig | 0.57 | 8.8 | 0.01 | May 23, 2022 | Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory. | ||
| CVE-2022-29002 | — | Hig | 0.57 | 8.8 | 0.00 | May 23, 2022 | A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add. | |
| CVE-2022-28999 | Hig | 0.57 | 8.8 | 0.01 | May 23, 2022 | Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binary devcpp.exe. | ||
| CVE-2022-31489 | Hig | 0.49 | 7.5 | 0.01 | May 23, 2022 | Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection. | ||
| CVE-2022-31488 | Hig | 0.49 | 7.5 | 0.01 | May 23, 2022 | Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection. | ||
| CVE-2022-31487 | Hig | 0.49 | 7.5 | 0.01 | May 23, 2022 | Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection. | ||
| CVE-2022-1467 | Hig | 0.48 | 7.4 | 0.01 | May 23, 2022 | Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is… | ||
| CVE-2022-31467 | Hig | 0.51 | 7.9 | 0.00 | May 23, 2022 | A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for required DLLs and then not… | ||
| CVE-2022-31466 | Hig | 0.51 | 7.9 | 0.00 | May 23, 2022 | Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploiting the time between detecting a file as… | ||
| CVE-2021-32935 | Hig | 0.57 | 8.8 | 0.02 | May 23, 2022 | The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation. | ||
| CVE-2022-28944 | Hig | 0.57 | 8.8 | 0.01 | May 23, 2022 | Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan… | ||
| CVE-2022-30016 | Hig | 0.57 | 8.8 | 0.01 | May 23, 2022 | Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info. | ||
| CVE-2022-30014 | Hig | 0.57 | 8.8 | 0.01 | May 23, 2022 | Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account. | ||
| CVE-2021-41714 | Hig | 0.00 | 7.7 | 0.01 | May 23, 2022 | In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage. | ||
| CVE-2022-28998 | Hig | 0.53 | 8.1 | 0.02 | May 23, 2022 | Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code. | ||
| CVE-2022-28997 | Hig | 0.49 | 7.5 | 0.02 | May 23, 2022 | CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/. | ||
| CVE-2021-42586 | Hig | 0.57 | 8.8 | 0.01 | May 23, 2022 | A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file. | ||
| CVE-2021-42585 | Hig | 0.57 | 8.8 | 0.01 | May 23, 2022 | A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file. | ||
| CVE-2022-1809 | Hig | 0.00 | 7.8 | 0.01 | May 21, 2022 | Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0. | ||
| CVE-2022-31268 | Hig | 0.50 | 7.5 | 0.10 | May 21, 2022 | A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname). | ||
| CVE-2022-31264 | — | Hig | 0.42 | 7.5 | 0.01 | May 21, 2022 | Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program. | |
| CVE-2022-1752 | Hig | 0.00 | 8.0 | 0.02 | May 21, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2. | ||
| CVE-2022-29216 | Hig | 0.44 | 7.8 | 0.01 | May 21, 2022 | TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shell. This code path was maintained for compatibility reasons… |
- risk 0.51cvss 7.8epss 0.01
A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.
- risk 0.47cvss 7.2epss 0.05
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.
- risk 0.46cvss 7.1epss 0.01
VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to a…
- risk 0.51cvss 7.8epss 0.01
A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have unspecified other impact via a crafted text document.
- risk 0.51cvss 7.8epss 0.01
A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document.
- risk 0.51cvss 7.8epss 0.01
A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document.
- risk 0.51cvss 7.8epss 0.00
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This…
- risk 0.51cvss 7.8epss 0.01
Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result in a system crash or allow an attacker to remotely execute arbitrary code.
- risk 0.51cvss 7.8epss 0.01
Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code.
- risk 0.53cvss 8.2epss 0.01
The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code.
- risk 0.57cvss 8.8epss 0.02
IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.
- risk 0.42cvss 7.5epss 0.01
JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may be critical in a situation where the highest levels of…
- risk 0.53cvss 8.1epss 0.04
A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions is possible. Firewalling or disabling the service is recommended.
- risk 0.49cvss 7.5epss 0.01
An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback ID of the configured identity source. A…
- risk 0.57cvss 8.8epss 0.01
Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id.
- risk 0.49cvss 7.5epss 0.01
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can cause a buffer overflow by providing the Azure RTOS USBX host stack a HUB descriptor with `bNbPorts` set to a value greater than `UX_MAX_TT` which defaults to…
- risk 0.51cvss 8.8epss 0.05
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully…
- risk 0.42cvss 7.5epss 0.01
Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a possible consensus split given maliciously-crafted `AttesterSlashing` or `ProposerSlashing` being included on-chain. Because the developers represent `uint64`…
- risk 0.41cvss 7.4epss 0.01
PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported.…
- risk 0.46cvss 8.1epss 0.01
Path Traversal in GitHub repository filegator/filegator prior to 7.8.0.
- risk 0.57cvss 8.8epss 0.01
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product.
- risk 0.57cvss 8.8epss 0.01
ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=delete_response, id.
- risk 0.57cvss 8.8epss 0.01
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
- risk 0.51cvss 7.8epss 0.05
A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through…
- risk 0.49cvss 7.5epss 0.01
mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.
- risk 0.53cvss 8.1epss 0.01
imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost.
- risk 0.49cvss 7.5epss 0.01
Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH.
- risk 0.57cvss 8.8epss 0.01
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.
- risk 0.57cvss 8.8epss 0.00
A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.
- risk 0.57cvss 8.8epss 0.01
Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binary devcpp.exe.
- risk 0.49cvss 7.5epss 0.01
Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection.
- risk 0.49cvss 7.5epss 0.01
Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection.
- risk 0.49cvss 7.5epss 0.01
Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.
- risk 0.48cvss 7.4epss 0.01
Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is…
- risk 0.51cvss 7.9epss 0.00
A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for required DLLs and then not…
- risk 0.51cvss 7.9epss 0.00
Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploiting the time between detecting a file as…
- risk 0.57cvss 8.8epss 0.02
The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation.
- risk 0.57cvss 8.8epss 0.01
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan…
- risk 0.57cvss 8.8epss 0.01
Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.
- risk 0.57cvss 8.8epss 0.01
Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.
- risk 0.00cvss 7.7epss 0.01
In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage.
- risk 0.53cvss 8.1epss 0.02
Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code.
- risk 0.49cvss 7.5epss 0.02
CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/.
- risk 0.57cvss 8.8epss 0.01
A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
- risk 0.57cvss 8.8epss 0.01
A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
- risk 0.00cvss 7.8epss 0.01
Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.
- risk 0.50cvss 7.5epss 0.10
A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).
- risk 0.42cvss 7.5epss 0.01
Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program.
- risk 0.00cvss 8.0epss 0.02
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.
- risk 0.44cvss 7.8epss 0.01
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shell. This code path was maintained for compatibility reasons…