2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34385 | MEDIUM | 5.5 | 0.1% | Feb 11, 2023 | SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) con... |
| CVE-2022-44261 | MEDIUM | 6.1 | 0.5% | Feb 10, 2023 | Avery Dennison Monarch Printer M9855 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-34377 | MEDIUM | 6.7 | 0.2% | Feb 10, 2023 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. ... |
| CVE-2022-34376 | MEDIUM | 5.5 | 0.1% | Feb 10, 2023 | Dell PowerEdge BIOS and Dell Precision BIOS contain an improper input validation vulnerability. A local authenticated... |
| CVE-2022-34366 | MEDIUM | 6.5 | 0.5% | Feb 10, 2023 | Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerabili... |
| CVE-2022-34364 | MEDIUM | 4.4 | 0.2% | Feb 10, 2023 | Dell BSAFE SSL-J, versions before 6.5 and version 7.0 contain a debug message revealing unnecessary information vulne... |
| CVE-2022-33934 | MEDIUM | 4.8 | 0.4% | Feb 10, 2023 | Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A rem... |
| CVE-2022-46650 | MEDIUM | 4.9 | 12.3% | Feb 10, 2023 | Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACE... |
| CVE-2022-24410 | MEDIUM | 4.2 | 0.2% | Feb 10, 2023 | Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the... |
| CVE-2022-34454 | MEDIUM | 6.7 | 0.2% | Feb 10, 2023 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user cou... |
| CVE-2022-21940 | MEDIUM | 6.1 | 0.4% | Feb 9, 2023 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool... |
| CVE-2022-21939 | MEDIUM | 6.1 | 0.5% | Feb 9, 2023 | Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 pr... |
| CVE-2022-43552 | MEDIUM | 5.9 | 2.5% | Feb 9, 2023 | A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports... |
| CVE-2022-48296 | MEDIUM | 5.3 | 0.3% | Feb 9, 2023 | The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users... |
| CVE-2022-48293 | MEDIUM | 6.5 | 0.2% | Feb 9, 2023 | The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentia... |
| CVE-2022-48292 | MEDIUM | 6.5 | 0.2% | Feb 9, 2023 | The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect ... |
| CVE-2022-30564 | MEDIUM | 5.3 | 0.4% | Feb 9, 2023 | Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a spe... |
| CVE-2022-38778 | MEDIUM | 6.5 | 0.9% | Feb 8, 2023 | A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated us... |
| CVE-2022-4304 | MEDIUM | 5.9 | 16.2% | Feb 8, 2023 | A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a p... |
| CVE-2022-45755 | MEDIUM | 5.4 | 0.4% | Feb 8, 2023 | Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page ... |
| CVE-2022-35720 | MEDIUM | 5.5 | 0.1% | Feb 8, 2023 | IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptogr... |
| CVE-2022-34362 | MEDIUM | 4.6 | 0.4% | Feb 8, 2023 | IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the H... |
| CVE-2022-2094 | MEDIUM | 6.1 | 0.5% | Feb 8, 2023 | The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back ... |
| CVE-2022-45192 | MEDIUM | 6.5 | 0.2% | Feb 8, 2023 | An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of servi... |
| CVE-2022-45191 | MEDIUM | 6.5 | 0.2% | Feb 8, 2023 | An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of servi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now