| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-28434 | — | Cri | 0.61 | 9.4 | 0.01 | Aug 2, 2022 | This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js. | |
| CVE-2020-28423 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | This affects all versions of package monorepo-build. | |
| CVE-2022-35422 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php. | ||
| CVE-2022-34956 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php. | ||
| CVE-2022-34955 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_topusers.php. | ||
| CVE-2022-34954 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php. | ||
| CVE-2022-34953 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php. | ||
| CVE-2022-34952 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php. | ||
| CVE-2022-34951 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php. | ||
| CVE-2022-34950 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editproduct.php. | |
| CVE-2022-34949 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php. | ||
| CVE-2022-34948 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbrand.php. | |
| CVE-2022-34947 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php. | ||
| CVE-2022-34946 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php. | ||
| CVE-2022-34945 | Cri | 0.64 | 9.8 | 0.01 | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php. | ||
| CVE-2022-31321 | Cri | 0.59 | 9.1 | 0.01 | Aug 1, 2022 | The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input. | ||
| CVE-2022-31183 | Cri | 0.52 | 9.1 | 0.01 | Aug 1, 2022 | fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `requestCert = true` is ignored, peer certificate verification is skipped, and the connection proceeds. The vulnerability is limited to:… | ||
| CVE-2022-31181 | Cri | 0.57 | 9.8 | 0.05 | Aug 1, 2022 | PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised… | ||
| CVE-2022-31180 | Cri | 0.57 | 9.8 | 0.02 | Aug 1, 2022 | Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only impacts users that use the `escape` or `escapeAll` functions with the `interpolation` option set to… | ||
| CVE-2022-2595 | Cri | 0.00 | 10.0 | 0.01 | Aug 1, 2022 | Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1. | ||
| CVE-2022-36301 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2022 | BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password. | ||
| CVE-2022-26437 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2022 | In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WSAP00103831; Issue ID: WSAP00103831. | ||
| CVE-2022-2317 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2022 | The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter. | ||
| CVE-2022-1950 | Cri | 0.64 | 9.8 | 0.04 | Aug 1, 2022 | The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection | ||
| CVE-2022-27255 | Cri | 0.67 | 9.8 | 0.37 | Aug 1, 2022 | In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code without authentication via a crafted SIP packet that contains malicious SDP data. | ||
| CVE-2022-31775 | Cri | 0.59 | 9.1 | 0.01 | Aug 1, 2022 | IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose… | ||
| CVE-2022-30083 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2022 | EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application appears to evaluate user input as code (remote). | ||
| CVE-2022-34531 | Cri | 0.66 | 9.8 | 0.23 | Jul 29, 2022 | DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php. | ||
| CVE-2022-34496 | Cri | 0.64 | 9.8 | 0.01 | Jul 29, 2022 | Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature. | ||
| CVE-2022-22280 | Cri | 0.64 | 9.8 | 0.09 | Jul 29, 2022 | Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3.1-SP2-Hotfix1, Analytics On-Prem 2.5.0.3-2520 and earlier versions. | ||
| CVE-2022-35643 | Cri | 0.59 | 9.1 | 0.01 | Jul 29, 2022 | IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM X-Force ID: 230956. | ||
| CVE-2022-1277 | Cri | 0.61 | 9.4 | 0.01 | Jul 29, 2022 | Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability. | ||
| CVE-2022-34558 | — | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2022 | WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package. | |
| CVE-2022-34555 | Cri | 0.65 | 9.8 | 0.20 | Jul 28, 2022 | TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a crafted packet. | ||
| CVE-2021-41556 | Cri | 0.58 | 10.0 | 0.02 | Jul 28, 2022 | sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script… | ||
| CVE-2022-2564 | — | Cri | 0.59 | 9.8 | 0.33 | Jul 28, 2022 | Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6. | |
| CVE-2016-4991 | — | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2022 | Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This… | |
| CVE-2022-30315 | Cri | 0.64 | 9.8 | 0.01 | Jul 28, 2022 | Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity. According to FSCT-2022-0053, there is a Honeywell Experion PKS Safety Manager insufficient logic security controls issue. The affected components are… | ||
| CVE-2022-22683 | Cri | 0.65 | 10.0 | 0.01 | Jul 28, 2022 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors. | ||
| CVE-2022-36992 | Cri | 0.64 | 9.9 | 0.01 | Jul 28, 2022 | An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on… | ||
| CVE-2022-36990 | Cri | 0.62 | 9.6 | 0.01 | Jul 28, 2022 | An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write arbitrary files to… | ||
| CVE-2022-2010 | Cri | 0.61 | 9.3 | 0.01 | Jul 28, 2022 | Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | ||
| CVE-2022-1853 | Cri | 0.62 | 9.6 | 0.01 | Jul 27, 2022 | Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | ||
| CVE-2022-36956 | Cri | 0.59 | 9.0 | 0.00 | Jul 27, 2022 | In Veritas NetBackup, the NetBackup Client allows arbitrary command execution from any remote host that has access to a valid host-id NetBackup certificate/private key from the same domain. The affects 9.0.x through 9.0.0.1 and 9.1.x through 9.1.0.1. | ||
| CVE-2022-36954 | Cri | 0.64 | 9.9 | 0.01 | Jul 27, 2022 | In Veritas NetBackup OpsCenter, under specific conditions, an authenticated remote attacker may be able to create or modify OpsCenter user accounts. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. | ||
| CVE-2022-36951 | Cri | 0.64 | 9.8 | 0.01 | Jul 27, 2022 | In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly patched vulnerability. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. | ||
| CVE-2022-36950 | Cri | 0.64 | 9.8 | 0.01 | Jul 27, 2022 | In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloader manipulation. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. | ||
| CVE-2022-36949 | Cri | 0.60 | 9.3 | 0.00 | Jul 27, 2022 | In Veritas NetBackup OpsCenter, an attacker with local access to a NetBackup OpsCenter server could potentially escalate their privileges. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10. | ||
| CVE-2022-24405 | Cri | 0.64 | 9.8 | 0.03 | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API. | ||
| CVE-2022-23100 | Cri | 0.64 | 9.8 | 0.03 | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment). |
- risk 0.61cvss 9.4epss 0.01
This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
- risk 0.64cvss 9.8epss 0.01
This affects all versions of package monorepo-build.
- risk 0.64cvss 9.8epss 0.01
Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php.
- risk 0.64cvss 9.8epss 0.01
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php.
- risk 0.64cvss 9.8epss 0.01
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_topusers.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editproduct.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbrand.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php.
- risk 0.59cvss 9.1epss 0.01
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input.
- risk 0.52cvss 9.1epss 0.01
fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `requestCert = true` is ignored, peer certificate verification is skipped, and the connection proceeds. The vulnerability is limited to:…
- risk 0.57cvss 9.8epss 0.05
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised…
- risk 0.57cvss 9.8epss 0.02
Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only impacts users that use the `escape` or `escapeAll` functions with the `interpolation` option set to…
- risk 0.00cvss 10.0epss 0.01
Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.
- risk 0.64cvss 9.8epss 0.01
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.
- risk 0.64cvss 9.8epss 0.01
In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WSAP00103831; Issue ID: WSAP00103831.
- risk 0.64cvss 9.8epss 0.01
The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter.
- risk 0.64cvss 9.8epss 0.04
The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
- risk 0.67cvss 9.8epss 0.37
In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code without authentication via a crafted SIP packet that contains malicious SDP data.
- risk 0.59cvss 9.1epss 0.01
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose…
- risk 0.64cvss 9.8epss 0.01
EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application appears to evaluate user input as code (remote).
- risk 0.66cvss 9.8epss 0.23
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
- risk 0.64cvss 9.8epss 0.01
Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.
- risk 0.64cvss 9.8epss 0.09
Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3.1-SP2-Hotfix1, Analytics On-Prem 2.5.0.3-2520 and earlier versions.
- risk 0.59cvss 9.1epss 0.01
IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM X-Force ID: 230956.
- risk 0.61cvss 9.4epss 0.01
Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.
- risk 0.65cvss 9.8epss 0.20
TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a crafted packet.
- risk 0.58cvss 10.0epss 0.02
sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script…
- risk 0.59cvss 9.8epss 0.33
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.
- risk 0.64cvss 9.8epss 0.01
Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This…
- risk 0.64cvss 9.8epss 0.01
Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity. According to FSCT-2022-0053, there is a Honeywell Experion PKS Safety Manager insufficient logic security controls issue. The affected components are…
- risk 0.65cvss 10.0epss 0.01
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors.
- risk 0.64cvss 9.9epss 0.01
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on…
- risk 0.62cvss 9.6epss 0.01
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write arbitrary files to…
- risk 0.61cvss 9.3epss 0.01
Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- risk 0.62cvss 9.6epss 0.01
Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
- risk 0.59cvss 9.0epss 0.00
In Veritas NetBackup, the NetBackup Client allows arbitrary command execution from any remote host that has access to a valid host-id NetBackup certificate/private key from the same domain. The affects 9.0.x through 9.0.0.1 and 9.1.x through 9.1.0.1.
- risk 0.64cvss 9.9epss 0.01
In Veritas NetBackup OpsCenter, under specific conditions, an authenticated remote attacker may be able to create or modify OpsCenter user accounts. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
- risk 0.64cvss 9.8epss 0.01
In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly patched vulnerability. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
- risk 0.64cvss 9.8epss 0.01
In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloader manipulation. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
- risk 0.60cvss 9.3epss 0.00
In Veritas NetBackup OpsCenter, an attacker with local access to a NetBackup OpsCenter server could potentially escalate their privileges. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
- risk 0.64cvss 9.8epss 0.03
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
- risk 0.64cvss 9.8epss 0.03
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).