2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-48353 | CRITICAL | 9.8 | 0.5% | Mar 27, 2023 | Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege esc... |
| CVE-2022-48349 | CRITICAL | 9.1 | 0.5% | Mar 27, 2023 | The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentia... |
| CVE-2022-48348 | CRITICAL | 9.1 | 0.4% | Mar 27, 2023 | The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability ma... |
| CVE-2022-4126 | CRITICAL | 9.8 | 0.6% | Mar 27, 2023 | Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and P... |
| CVE-2022-45597 | CRITICAL | 9.8 | 0.7% | Mar 24, 2023 | ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability b... |
| CVE-2022-42499 | CRITICAL | 9.8 | 0.5% | Mar 24, 2023 | In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. T... |
| CVE-2022-42498 | CRITICAL | 9.8 | 0.5% | Mar 24, 2023 | In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to re... |
| CVE-2022-20532 | CRITICAL | 9.8 | 0.5% | Mar 24, 2023 | In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. Thi... |
| CVE-2022-42948 | CRITICAL | 9.8 | 2.7% | Mar 24, 2023 | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted... |
| CVE-2022-28495 | CRITICAL | 9.8 | 2.4% | Mar 24, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebW... |
| CVE-2022-36413 | CRITICAL | 9.1 | 3.1% | Mar 23, 2023 | Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset o... |
| CVE-2022-28496 | CRITICAL | 9.8 | 1.4% | Mar 23, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswor... |
| CVE-2022-28497 | CRITICAL | 9.8 | 1.4% | Mar 23, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_wri... |
| CVE-2022-28493 | CRITICAL | 9.8 | 0.7% | Mar 23, 2023 | A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service, |
| CVE-2022-28491 | CRITICAL | 9.8 | 4.7% | Mar 23, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost functio... |
| CVE-2022-28492 | CRITICAL | 9.8 | 1.3% | Mar 23, 2023 | TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login. |
| CVE-2022-22512 | CRITICAL | 9.8 | 0.7% | Mar 23, 2023 | Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker... |
| CVE-2022-28494 | CRITICAL | 9.8 | 2.6% | Mar 23, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgr... |
| CVE-2022-45637 | CRITICAL | 9.8 | 0.8% | Mar 21, 2023 | An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via ins... |
| CVE-2022-43663 | CRITICAL | 9.8 | 14.0% | Mar 20, 2023 | An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.0... |
| CVE-2022-4933 | CRITICAL | 9.8 | 0.6% | Mar 20, 2023 | A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice u... |
| CVE-2022-43605 | CRITICAL | 9.8 | 14.4% | Mar 16, 2023 | An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack G... |
| CVE-2022-43604 | CRITICAL | 9.8 | 14.4% | Mar 16, 2023 | An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack G... |
| CVE-2022-43441 | CRITICAL | 9.8 | 2.4% | Mar 16, 2023 | A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A ... |
| CVE-2022-39216 | CRITICAL | 9.8 | 0.9% | Mar 14, 2023 | Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now