| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2310 | Cri | 0.65 | 10.0 | 0.01 | Jul 27, 2022 | An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is… | ||
| CVE-2022-36129 | Cri | 0.59 | 9.1 | 0.01 | Jul 26, 2022 | HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or… | ||
| CVE-2022-30274 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2022 | The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB… | ||
| CVE-2022-30271 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2022 | The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default. | ||
| CVE-2022-30270 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2022 | The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is… | ||
| CVE-2022-31207 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2022 | The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects and control logic to the PLC. This… | ||
| CVE-2022-31206 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2022 | The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. These PLCs are programmed using the SYMAC Studio engineering software (which compiles IEC 61131-3 conformant POU code to native… | ||
| CVE-2022-30273 | Cri | 0.64 | 9.8 | 0.00 | Jul 26, 2022 | The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode… | ||
| CVE-2022-29958 | Cri | 0.64 | 9.8 | 0.00 | Jul 26, 2022 | JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with… | ||
| CVE-2022-29953 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2022 | The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality. | ||
| CVE-2022-29952 | Cri | 0.59 | 9.1 | 0.01 | Jul 26, 2022 | Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC)… | ||
| CVE-2022-29951 | Cri | 0.59 | 9.1 | 0.01 | Jul 26, 2022 | JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and… | ||
| CVE-2022-36412 | Cri | 0.64 | 9.8 | 0.06 | Jul 26, 2022 | In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.) | ||
| CVE-2022-36161 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2022 | Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | ||
| CVE-2022-34989 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2022 | Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php. | ||
| CVE-2022-34577 | Cri | 0.64 | 9.8 | 0.02 | Jul 25, 2022 | A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request. | ||
| CVE-2022-35131 | Cri | 0.52 | 9.0 | 0.02 | Jul 25, 2022 | Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles. | ||
| CVE-2022-34907 | Cri | 0.65 | 9.8 | 0.16 | Jul 25, 2022 | An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform. | ||
| CVE-2022-35869 | Cri | 0.69 | 9.8 | 0.60 | Jul 25, 2022 | This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within… | ||
| CVE-2022-24083 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2022 | Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. | ||
| CVE-2022-35649 | Cri | 0.01 | 9.8 | 0.08 | Jul 25, 2022 | The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this… | ||
| CVE-2022-33965 | Cri | 0.61 | 9.3 | 0.04 | Jul 25, 2022 | Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress. | ||
| CVE-2022-1312 | Cri | 0.62 | 9.6 | 0.01 | Jul 25, 2022 | Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. | ||
| CVE-2022-1309 | Cri | 0.62 | 9.6 | 0.01 | Jul 25, 2022 | Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | ||
| CVE-2022-0670 | Cri | 0.59 | 9.1 | 0.01 | Jul 25, 2022 | A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise… | ||
| CVE-2020-28447 | — | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2022 | This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath) | |
| CVE-2020-28446 | — | Cri | 0.57 | 9.8 | 0.03 | Jul 25, 2022 | The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js. | |
| CVE-2020-28445 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2022 | This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function. | ||
| CVE-2020-28443 | — | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2022 | This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js. | |
| CVE-2020-28438 | — | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2022 | This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js | |
| CVE-2020-28435 | Cri | 0.61 | 9.4 | 0.01 | Jul 25, 2022 | This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js. | ||
| CVE-2022-36446 | Cri | 0.11 | 9.8 | 0.96 | Jul 25, 2022 | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command. | ||
| CVE-2022-34115 | Cri | 0.57 | 9.8 | 0.01 | Jul 22, 2022 | DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId. | ||
| CVE-2022-34113 | Cri | 0.64 | 9.8 | 0.01 | Jul 22, 2022 | An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin. | ||
| CVE-2022-25759 | — | Cri | 0.58 | 9.9 | 0.11 | Jul 22, 2022 | The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload. | |
| CVE-2022-30998 | Cri | 0.59 | 9.1 | 0.01 | Jul 22, 2022 | Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress. | ||
| CVE-2022-34983 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2022 | The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party. | ||
| CVE-2022-34982 | Cri | 0.64 | 9.8 | 0.01 | Jul 22, 2022 | The eziod package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. | ||
| CVE-2022-34981 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2022 | The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. | ||
| CVE-2022-34509 | Cri | 0.64 | 9.8 | 0.01 | Jul 22, 2022 | The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party. | ||
| CVE-2022-34501 | Cri | 0.57 | 9.8 | 0.01 | Jul 22, 2022 | The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party. | ||
| CVE-2022-34500 | Cri | 0.57 | 9.8 | 0.01 | Jul 22, 2022 | The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party. | ||
| CVE-2022-2143 | Cri | 0.71 | 9.8 | 0.59 | Jul 22, 2022 | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. | ||
| CVE-2022-0977 | Cri | 0.62 | 9.6 | 0.01 | Jul 21, 2022 | Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2022-0973 | Cri | 0.62 | 9.6 | 0.01 | Jul 21, 2022 | Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2022-34487 | Cri | 0.64 | 9.8 | 0.03 | Jul 21, 2022 | Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress. | ||
| CVE-2022-33198 | Cri | 0.64 | 9.8 | 0.03 | Jul 21, 2022 | Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress. | ||
| CVE-2022-28700 | Cri | 0.59 | 9.1 | 0.02 | Jul 21, 2022 | Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress. | ||
| CVE-2022-20861 | Cri | 0.64 | 9.8 | 0.01 | Jul 21, 2022 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the… | ||
| CVE-2022-20858 | Cri | 0.64 | 9.8 | 0.01 | Jul 21, 2022 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the… |
- risk 0.65cvss 10.0epss 0.01
An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is…
- risk 0.59cvss 9.1epss 0.01
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or…
- risk 0.64cvss 9.8epss 0.01
The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB…
- risk 0.64cvss 9.8epss 0.01
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.
- risk 0.64cvss 9.8epss 0.01
The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is…
- risk 0.64cvss 9.8epss 0.01
The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects and control logic to the PLC. This…
- risk 0.64cvss 9.8epss 0.01
The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. These PLCs are programmed using the SYMAC Studio engineering software (which compiles IEC 61131-3 conformant POU code to native…
- risk 0.64cvss 9.8epss 0.00
The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode…
- risk 0.64cvss 9.8epss 0.00
JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with…
- risk 0.64cvss 9.8epss 0.01
The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.
- risk 0.59cvss 9.1epss 0.01
Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC)…
- risk 0.59cvss 9.1epss 0.01
JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and…
- risk 0.64cvss 9.8epss 0.06
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
- risk 0.64cvss 9.8epss 0.01
Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
- risk 0.64cvss 9.8epss 0.01
Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php.
- risk 0.64cvss 9.8epss 0.02
A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
- risk 0.52cvss 9.0epss 0.02
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
- risk 0.65cvss 9.8epss 0.16
An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.
- risk 0.69cvss 9.8epss 0.60
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within…
- risk 0.64cvss 9.8epss 0.01
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
- risk 0.01cvss 9.8epss 0.08
The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this…
- risk 0.61cvss 9.3epss 0.04
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.
- risk 0.62cvss 9.6epss 0.01
Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
- risk 0.62cvss 9.6epss 0.01
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
- risk 0.59cvss 9.1epss 0.01
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise…
- risk 0.64cvss 9.8epss 0.01
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)
- risk 0.57cvss 9.8epss 0.03
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
- risk 0.64cvss 9.8epss 0.01
This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.
- risk 0.64cvss 9.8epss 0.01
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
- risk 0.64cvss 9.8epss 0.01
This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js
- risk 0.61cvss 9.4epss 0.01
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.
- risk 0.11cvss 9.8epss 0.96
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
- risk 0.57cvss 9.8epss 0.01
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
- risk 0.64cvss 9.8epss 0.01
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
- risk 0.58cvss 9.9epss 0.11
The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.
- risk 0.59cvss 9.1epss 0.01
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.
- risk 0.64cvss 9.8epss 0.02
The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party.
- risk 0.64cvss 9.8epss 0.01
The eziod package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
- risk 0.64cvss 9.8epss 0.02
The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
- risk 0.64cvss 9.8epss 0.01
The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party.
- risk 0.57cvss 9.8epss 0.01
The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
- risk 0.57cvss 9.8epss 0.01
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
- risk 0.71cvss 9.8epss 0.59
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.
- risk 0.62cvss 9.6epss 0.01
Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
- risk 0.62cvss 9.6epss 0.01
Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.64cvss 9.8epss 0.03
Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.
- risk 0.64cvss 9.8epss 0.03
Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.
- risk 0.59cvss 9.1epss 0.02
Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
- risk 0.64cvss 9.8epss 0.01
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the…
- risk 0.64cvss 9.8epss 0.01
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the…