Show filters
1,028 Total Results
Displaying 91-100 of 1,028
Sort by:
Attacker Value
Unknown
CVE-2022-44048
Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version of d8s-htm is 0.1.0.
0
Attacker Value
Unknown
CVE-2022-43304
Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version of d8s-htm is 0.1.0.
0
Attacker Value
Unknown
CVE-2022-43306
Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-dates package. The affected version of d8s-htm is 0.1.0.
0
Attacker Value
Unknown
CVE-2022-3537
Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP
0
Attacker Value
Unknown
CVE-2022-43061
Disclosure Date: November 03, 2022 (last updated February 24, 2025)
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-40981
Disclosure Date: November 03, 2022 (last updated February 24, 2025)
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on the server, which could override sensitive and useful existing files on the filesystem, fill the hard disk to full capacity, or compromise the affected device or computers with administrator level privileges connected to the affected device.
0
Attacker Value
Unknown
CVE-2022-43085
Disclosure Date: November 01, 2022 (last updated February 24, 2025)
An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-43083
Disclosure Date: November 01, 2022 (last updated February 24, 2025)
An arbitrary file upload vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-3575
Disclosure Date: November 01, 2022 (last updated February 24, 2025)
Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload without authentication by using the configuration upload function. This could lead to a complete compromise of the FDS102 device.
0
Attacker Value
Unknown
CVE-2022-39019
Disclosure Date: October 31, 2022 (last updated February 24, 2025)
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.
0