Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-40894PUBLISHED: 2022-06-24A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in underscore-99xp v1.7.2 when the deepValueSearch function is called.
CVE-2022-32997PUBLISHED: 2022-06-24The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
CVE-2022-32998PUBLISHED: 2022-06-24The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
CVE-2022-32999PUBLISHED: 2022-06-24The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
CVE-2022-33000PUBLISHED: 2022-06-24The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
User Rank: Ninja
12/9/2014 | 2:02:45 PM
better written as shattered trust. the Snowden affair followed by the 60 minutes expose on PCI fraud has finished the job. we have to fire the coach and the manager and get new help in here .