ZeroHour

Vulnerabilities

16 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-34500
+1 in the same advisory: …34501
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

NVD description · AI analysis pending
9.81%
  • pypi pypi
CVE-2022-34056
The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package.

The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi watertools
CVE-2022-34055
The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package.

The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi drxhello
CVE-2022-34054
The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package.

The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi perdido
CVE-2022-34053
The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package.

The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi dr-web-engine
CVE-2022-33004
The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package.

The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi beginner
CVE-2022-33003
The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package.

The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi watools
CVE-2022-33002
The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package.

The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi explore
CVE-2022-33001
The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package.

The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi aamiles
CVE-2022-33000
The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package.

The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi ml-scanner
CVE-2022-32999
The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package.

The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi cloudlabeling
CVE-2022-32998
The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package.

The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi cryptoasset-data-downloader
CVE-2022-32997
The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package.

The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi rootinteractive
CVE-2022-32996
The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package.

The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

NVD description · AI analysis pending
9.82% PoC
  • pypi django-navbar-client
CVE-2020-15904
A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.

A buffer overflow in the patching routine of bsdiff4 before 1.2.0 allows an attacker to write to heap memory (beyond allocated bounds) via a crafted patch file.

NVD description · AI analysis pending
7.81%
  • pypi bsdiff4