Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-37189

EPSS 0.43% · P63
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-37189

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
DDMAL MEI2Volpiano 0.8.2 is vulnerable to XML External Entity (XXE), leading to a Denial of Service. This occurs due to the usage of the unsafe 'xml.etree' library to parse untrusted XML input.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
DDMAL MEI2Volpiano 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
MEI2Volpiano是加拿大DDMAL开源的一个 Python 库。用于将 Neume 和 CWMN MEI 文件转换为 Volpiano 字符串。 DDMAL MEI2Volpiano 0.8.2版本存在安全漏洞,该漏洞源于使用了不安全的xml.etree库来解析不可信的XML输入导致容易受到攻击者的XML外部实体攻击造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2022-37189

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-37189

登录查看更多情报信息。

Same Patch Batch · n/a · 2022-09-07 · 37 CVEs total

CVE-2022-371088.7 HIGHSecuronix SNYPR 注入漏洞
CVE-2022-36659xhyve 代码问题漏洞
CVE-2022-38309Tenda AC18 缓冲区错误漏洞
CVE-2022-38314Tenda AC18 缓冲区错误漏洞
CVE-2022-30078NETGEAR R6300v2和NETGEAR R6200v2 操作系统命令注入漏洞
CVE-2022-30312Honeywell Trend Controls IQ Series that utilize Inter-Controller (IC) protocol 安全漏洞
CVE-2022-31414D-Link DIR-1960 安全漏洞
CVE-2022-36587Tenda G3 安全漏洞
CVE-2022-36661xhyve 代码问题漏洞
CVE-2022-36660xhyve 缓冲区错误漏洞
CVE-2022-38310Tenda AC18 缓冲区错误漏洞
CVE-2022-37780多款Phicomm产品安全漏洞
CVE-2022-36539Eigen&Wijzer Ouderapp 安全漏洞
CVE-2022-37731ftcms 跨站脚本漏洞
CVE-2022-37730ftcms 跨站请求伪造漏洞
CVE-2022-35513Blink1Control2 加密问题漏洞
CVE-2022-36271Outbyte PC Repair 代码问题漏洞
CVE-2022-40023SQLAlchemy 安全漏洞
CVE-2022-38247Nagios XI 跨站脚本漏洞
CVE-2022-36586Tenda G3 安全漏洞

Showing top 20 of 37 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2022-37189

No comments yet


Leave a comment