VYPR

Vendor CVEs

Jqhph

All CVEs

70 total · sorted by risk
  • CVE-2025-65656CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.

  • CVE-2024-48206CriOct 29, 2024
    risk 0.64cvss 9.8epss 0.01

    A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code.

  • CVE-2022-34064CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.01

    The Zibal package in PyPI v1.0.0 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-34056CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-34055CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-34054CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-34053CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-33004CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-33003CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-33002CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-33001CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-33000CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-32999CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-32998CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-32997CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-32996CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2021-20204CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This…

  • CVE-2018-20027CriDec 17, 2018
    risk 0.64cvss 9.8epss 0.02

    The yaml_parse.load method in Pylearn2 allows code injection.

  • CVE-2018-12557CriJun 19, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a task is ignored. If the unreachable error occurred in a task used with a loop variable (e.g., with_items), the contents of the loop items would be printed in the…

  • CVE-2026-10731CriJun 9, 2026
    risk 0.60cvss epss 0.00

    SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-factor authentication (2FA) functionality can be accessed without prior authentication, allowing unauthenticated…

  • CVE-2026-6657HigJun 3, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Origin` header, which only anchors at the…

  • CVE-2026-38360CriMay 8, 2026
    risk 0.57cvss 9.8epss 0.06

    Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, BaseHttpRequestHandler.get_temp_root(), BaseHttpRequestHandler._post() components.

  • CVE-2022-34501CriJul 22, 2022
    risk 0.57cvss 9.8epss 0.01

    The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

  • CVE-2022-34500CriJul 22, 2022
    risk 0.57cvss 9.8epss 0.01

    The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

  • CVE-2016-0727HigApr 14, 2017
    risk 0.54cvss 7.8epss 0.01

    The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 16.04 LTS allows local users with access to the ntp account…

  • CVE-2024-8007HigAug 21, 2024
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could…

  • CVE-2014-5282HigFeb 6, 2018
    risk 0.53cvss 8.1epss 0.01

    Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.

  • CVE-2026-39832CriMay 22, 2026
    risk 0.52cvss 9.1epss 0.01

    When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client…

  • CVE-2022-28696HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in the Intel(R) Distribution for Python before version 2022.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2018-20159HigDec 15, 2018
    risk 0.51cvss 7.2epss 0.10

    i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with the administrator role to upload arbitrary files to the main website directory. Exploitation involves uploading a ".php" file…

  • CVE-2018-6552HigMay 31, 2018
    risk 0.51cvss 7.8epss 0.00

    Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers. The…

  • CVE-2026-50031HigJun 3, 2026
    risk 0.49cvss 7.5epss 0.00

    ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to…

  • CVE-2021-42521HigAug 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that…

  • CVE-2011-3147HigApr 22, 2019
    risk 0.49cvss 8.6epss 0.01

    Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.

  • CVE-2019-6690HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.09

    python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input…

  • CVE-2018-12088HigJun 10, 2018
    risk 0.49cvss 7.5epss 0.02

    S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or temporarily hide parts…

  • CVE-2026-44393HigJun 4, 2026
    risk 0.48cvss 7.4epss 0.00

    An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configured, the driver enables certificate chain validation but does…

  • CVE-2024-22017HigMar 19, 2024
    risk 0.48cvss 7.3epss 0.01

    setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users…

  • CVE-2026-11837HigJun 10, 2026
    risk 0.47cvss 7.3epss 0.00

    A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage…

  • CVE-2026-44246HigMay 12, 2026
    risk 0.47cvss 7.2epss 0.00

    nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net Issue Triage workflow in .github/workflows/issue-triage.yml is vulnerable to Agentic Workflow Injection. The workflow sets allowed_non_write_users: ${{…

  • CVE-2020-15904HigJul 22, 2020
    risk 0.44cvss 7.8epss 0.01

    A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.

  • CVE-2026-37737MedJun 5, 2026
    risk 0.42cvss 6.5epss 0.00

    sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/core.py that uses re.match without end-anchoring. This allows an attacker to bypass CORS origin allowlists by registering a domain that begins with a trusted…

  • CVE-2026-47066HigMay 25, 2026
    risk 0.42cvss 7.5epss 0.01

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc hackney allows Excessive Allocation. The Alt-Svc response header parser in src/hackney_altsvc.erl does not guarantee forward progress. When parse_token/2 receives a non-token, non-whitespace,…

  • CVE-2026-20238MedMay 20, 2026
    risk 0.42cvss 6.5epss 0.00

    In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.The app contains an `authorize.conf` configuration file…

  • CVE-2026-6659HigMay 8, 2026
    risk 0.42cvss 7.5epss 0.00

    Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

  • CVE-2026-38361HigMay 8, 2026
    risk 0.42cvss 7.5epss 0.03

    Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_uploader/httprequesthandler.py, dash_uploader/upload.py) trusts unsanitized, attacker-controlled upload parameters (e.g. flowTotalChunks)…

  • CVE-2026-41074HigMay 22, 2026
    risk 0.39cvss 7.1epss 0.00

    RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger arbitrary state-changing…

  • CVE-2026-9751MedJun 9, 2026
    risk 0.36cvss 5.5epss 0.00

    The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.

  • CVE-2024-29085MedNov 13, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper access control for some BigDL software maintained by Intel(R) before version 2.5.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2014-5509MedJan 8, 2018
    risk 0.36cvss 5.5epss 0.00

    clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.

Page 1 of 2