Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In November 2022
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.
CVSS Score
7.3
EPSS Score
0.0
Published
2022-11-07
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900.
CVSS Score
7.3
EPSS Score
0.0
Published
2022-11-07
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled twice.
CVSS Score
4.7
EPSS Score
0.0
Published
2022-11-07
A vulnerability classified as critical has been found in Maxon ERP. This affects an unknown part of the file /index.php/purchase_order/browse_data. The manipulation of the argument tb_search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213039.
CVSS Score
7.3
EPSS Score
0.001
Published
2022-11-07
Food Ordering Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /foms/all-orders.php?status=Cancelled%20by%20Customer.
CVSS Score
7.2
EPSS Score
0.001
Published
2022-11-07
An information disclosure vulnerability in the component vcs/downloadFiles.php?download=./search.php of Simple E-Learning System v1.0 allows attackers to read arbitrary files.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-11-07
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_inquiry.
CVSS Score
7.2
EPSS Score
0.001
Published
2022-11-07
Sanitization Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.
CVSS Score
6.5
EPSS Score
0.001
Published
2022-11-07
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_quote.
CVSS Score
7.2
EPSS Score
0.001
Published
2022-11-07
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version of d8s-htm is 0.1.0.
CVSS Score
9.8
EPSS Score
0.001
Published
2022-11-07


Contact Us

Shodan ® - All rights reserved