2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45275 | HIGH | 7.2 | 15.3% | Dec 12, 2022 | An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing Sy... |
| CVE-2022-42716 | HIGH | 8.8 | 1.3% | Dec 12, 2022 | An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make imp... |
| CVE-2022-41881 | HIGH | 7.5 | 1.5% | Dec 12, 2022 | Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackO... |
| CVE-2022-3999 | HIGH | 8.1 | 0.4% | Dec 12, 2022 | The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which cou... |
| CVE-2022-3989 | HIGH | 8.8 | 1.0% | Dec 12, 2022 | The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .ph... |
| CVE-2022-3981 | HIGH | 8.8 | 0.7% | Dec 12, 2022 | The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a... |
| CVE-2022-3925 | HIGH | 7.2 | 1.0% | Dec 12, 2022 | The buddybadges WordPress plugin through 1.0.0 does not sanitise and escape a parameter before using it in a SQL stateme... |
| CVE-2022-3912 | HIGH | 7.5 | 0.7% | Dec 12, 2022 | The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX ac... |
| CVE-2022-3605 | HIGH | 7.8 | 0.4% | Dec 12, 2022 | The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leadin... |
| CVE-2022-3359 | HIGH | 8.8 | 0.7% | Dec 12, 2022 | The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported... |
| CVE-2022-45997 | HIGH | 7.2 | 0.9% | Dec 12, 2022 | Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow. |
| CVE-2022-45996 | HIGH | 7.2 | 2.3% | Dec 12, 2022 | Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output. |
| CVE-2022-45980 | HIGH | 8.8 | 7.5% | Dec 12, 2022 | Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet . |
| CVE-2022-45979 | HIGH | 7.5 | 0.8% | Dec 12, 2022 | Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wif... |
| CVE-2022-45977 | HIGH | 8.8 | 2.1% | Dec 12, 2022 | Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function. |
| CVE-2022-45957 | HIGH | 7.5 | 11.5% | Dec 12, 2022 | ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow. |
| CVE-2022-45043 | HIGH | 8.8 | 2.2% | Dec 12, 2022 | Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set. |
| CVE-2022-45968 | HIGH | 8.8 | 1.0% | Dec 12, 2022 | Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (ev... |
| CVE-2022-44654 | HIGH | 7.5 | 0.8% | Dec 12, 2022 | Affected builds of Trend Micro Apex One and Apex One as a Service contain a monitor engine component that is complied wi... |
| CVE-2022-44653 | HIGH | 7.8 | 0.6% | Dec 12, 2022 | A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local... |
| CVE-2022-44652 | HIGH | 7.8 | 0.3% | Dec 12, 2022 | An improper handling of exceptional conditions vulnerability in Trend Micro Apex One and Apex One as a Service could all... |
| CVE-2022-44651 | HIGH | 7 | 0.2% | Dec 12, 2022 | A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a loca... |
| CVE-2022-44650 | HIGH | 7.8 | 0.3% | Dec 12, 2022 | A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as ... |
| CVE-2022-44649 | HIGH | 7.8 | 0.3% | Dec 12, 2022 | An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One... |
| CVE-2022-44533 | HIGH | 7.2 | 1.3% | Dec 12, 2022 | A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run ar... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now