CVE-2022-34822 - Path Traversal in CLUSTERPRO X & EXPRESSCLUSTER X (Windows) – How an Unauthenticated Attacker Can Take Over Your Server
In 2022, a serious vulnerability, CVE-2022-34822, was discovered in the leading cluster management and high-availability software from NEC—CLUSTERPRO X 5. for
CVE-2022-41208 An attacker with user privileges can alter a user's session.
To exploit the vulnerability, an attacker must be able to log in to the targeted application with user privileges. The update causes certain parameters of
CVE-2022-44313 PicoC 3.2.2 had an exploitable buffer overflow in the ExpressionCoerceUnsignedInteger function that could lead to remote code execution.
This can be exploited by attackers to execute arbitrary code as the user running the script.
The following PoC is available on GitHub. To install
CVE-2022-41662 - Out-of-Bounds Read in Siemens JT2Go & Teamcenter Visualization – Exploit Details and Patch Guidance
In October 2022, Siemens disclosed a critical vulnerability affecting several of its widely used industrial visualization tools – JT2Go and Teamcenter Visualization. Tracked as CVE-2022-
CVE-2022-36077 - How Sensitive Data Escaped Through Electron Redirects
Summary:
CVE-2022-36077 reveals a severe vulnerability in the Electron framework before versions 21..-beta.1, 20..1, 19..11, and 18.3.7.
Episode
00:00:00
00:00:00