Show filters
1,022 Total Results
Displaying 81-90 of 1,022
Sort by:
Attacker Value
Unknown

CVE-2022-44050

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-json package. The affected version of d8s-htm is 0.1.0.
Attacker Value
Unknown

CVE-2022-44049

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-grammars package. The affected version of d8s-htm is 0.1.0.
Attacker Value
Unknown

CVE-2022-44054

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-utility package. The affected version of d8s-htm is 0.1.0.
Attacker Value
Unknown

CVE-2022-44051

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.0.
Attacker Value
Unknown

CVE-2022-44048

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version of d8s-htm is 0.1.0.
Attacker Value
Unknown

CVE-2022-43304

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version of d8s-htm is 0.1.0.
Attacker Value
Unknown

CVE-2022-43306

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-dates package. The affected version of d8s-htm is 0.1.0.
Attacker Value
Unknown

CVE-2022-3537

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP
Attacker Value
Unknown

CVE-2022-43061

Disclosure Date: November 03, 2022 (last updated February 24, 2025)
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-40981

Disclosure Date: November 03, 2022 (last updated February 24, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on the server, which could override sensitive and useful existing files on the filesystem, fill the hard disk to full capacity, or compromise the affected device or computers with administrator level privileges connected to the affected device.