
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2022-35908 | Published 2023-09-29 | CVSS: 8.8 | ShadowTrackr CVSS: 6.8 | Summary: Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent. |
CVE: CVE-2022-3590 | Published 2022-12-14 | CVSS: 5.9 | ShadowTrackr CVSS: 6.9 | Summary: WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden. |
CVE: CVE-2022-35909 | Published 2022-08-19 | CVSS: 8.8 | ShadowTrackr CVSS: 6.8 | Summary: In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality. |
CVE: CVE-2022-35906 | Published 2022-07-15 | CVSS: 3.3 | ShadowTrackr CVSS: 0.2 | Summary: An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a DGN file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of DGN files could enable an attacker to read information in the context of the current process. |
CVE: CVE-2022-35905 | Published 2022-07-15 | CVSS: 3.3 | ShadowTrackr CVSS: 0.2 | Summary: An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an FBX file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of FBX files could enable an attacker to read information in the context of the current process. |
CVE: CVE-2022-35904 | Published 2022-07-15 | CVSS: 3.3 | ShadowTrackr CVSS: 0.2 | Summary: An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an IFC file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of IFC files could enable an attacker to read information in the context of the current process. |
CVE: CVE-2022-35903 | Published 2022-07-15 | CVSS: 3.3 | ShadowTrackr CVSS: 0.2 | Summary: An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a 3DS file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of 3DS files could enable an attacker to read information in the context of the current process. |
CVE: CVE-2022-35902 | Published 2022-07-15 | CVSS: 3.3 | ShadowTrackr CVSS: 0.2 | Summary: An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an OBJ file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of OBJ files could enable an attacker to read information in the context of the current process. |
CVE: CVE-2022-35901 | Published 2022-07-15 | CVSS: 3.3 | ShadowTrackr CVSS: 0.2 | Summary: An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a J2K file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of J2K files could enable an attacker to read information in the context of the current process. |
CVE: CVE-2022-35900 | Published 2022-07-15 | CVSS: 3.3 | ShadowTrackr CVSS: 0.2 | Summary: An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a JP2 file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of JP2 files could enable an attacker to read information in the context of the current process. |