pypi kayıtları
pypi üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %43,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Saldırı profili
Tüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2022-34056İstismar yok | The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package.pypi · watertools | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-32999İstismar yok | The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package.pypi · cloudlabeling | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-33001İstismar yok | The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package.pypi · aamiles | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-33002İstismar yok | The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package.pypi · explore | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-33003İstismar yok | The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package.pypi · watools | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-34053İstismar yok | The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package.pypi · dr-web-engine | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-34055İstismar yok | The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package.pypi · drxhello | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-32998İstismar yok | The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request packagepypi · cryptoasset-data-downloader | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-32996İstismar yok | The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package.pypi · django-navbar-client | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-32997İstismar yok | The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package.pypi · rootinteractive | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-33004İstismar yok | The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package.pypi · beginner | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-34054İstismar yok | The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package.pypi · perdido | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
40Planlayın | CVE-2022-33000İstismar yok | The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package.pypi · ml-scanner | Kritik9,8 | — | %2,0 | 24 Haz 2022 |
39İzleyin | CVE-2022-34500İstismar yok | The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.pypi · pypi | Kritik9,8 | — | %1,5 | 22 Tem 2022 |
39İzleyin | CVE-2022-34501İstismar yok | The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.pypi · pypi | Kritik9,8 | — | %1,5 | 22 Tem 2022 |
31İzleyin | CVE-2020-15904İstismar yok | A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via apypi · bsdiff4 · CWE-787 | Yüksek7,8 | — | %1,1 | 22 Tem 2020 |
- CVE-2022-3405640Planlayın
The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · watertools24 Haz 2022
- CVE-2022-3299940Planlayın
The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · cloudlabeling24 Haz 2022
- CVE-2022-3300140Planlayın
The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · aamiles24 Haz 2022
- CVE-2022-3300240Planlayın
The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · explore24 Haz 2022
- CVE-2022-3300340Planlayın
The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · watools24 Haz 2022
- CVE-2022-3405340Planlayın
The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · dr-web-engine24 Haz 2022
- CVE-2022-3405540Planlayın
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · drxhello24 Haz 2022
- CVE-2022-3299840Planlayın
The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package
KritikCVSS 9,8İstismar yokEPSS %2pypi · cryptoasset-data-downloader24 Haz 2022
- CVE-2022-3299640Planlayın
The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · django-navbar-client24 Haz 2022
- CVE-2022-3299740Planlayın
The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · rootinteractive24 Haz 2022
- CVE-2022-3300440Planlayın
The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · beginner24 Haz 2022
- CVE-2022-3405440Planlayın
The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · perdido24 Haz 2022
- CVE-2022-3300040Planlayın
The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package.
KritikCVSS 9,8İstismar yokEPSS %2pypi · ml-scanner24 Haz 2022
- CVE-2022-3450039İzleyin
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
KritikCVSS 9,8İstismar yokEPSS %2pypi · pypi22 Tem 2022
- CVE-2022-3450139İzleyin
The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
KritikCVSS 9,8İstismar yokEPSS %1pypi · pypi22 Tem 2022
- CVE-2020-1590431İzleyin
A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a
YüksekCVSS 7,8İstismar yokEPSS %1pypi · bsdiff422 Tem 2020