2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2794 | HIGH | 7.5 | 0.9% | Dec 12, 2022 | Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack. |
| CVE-2022-1038 | HIGH | 7.8 | 0.2% | Dec 12, 2022 | A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of pri... |
| CVE-2022-45797 | HIGH | 7.1 | 0.6% | Dec 12, 2022 | An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro ... |
| CVE-2022-41296 | HIGH | 8.8 | 0.5% | Dec 12, 2022 | IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou... |
| CVE-2022-3641 | HIGH | 8.8 | 0.6% | Dec 12, 2022 | Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows ... |
| CVE-2022-20968 | HIGH | 8.8 | 6.4% | Dec 12, 2022 | A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could... |
| CVE-2022-20690 | HIGH | 8.8 | 0.7% | Dec 12, 2022 | Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter ... |
| CVE-2022-20689 | HIGH | 8.8 | 0.6% | Dec 12, 2022 | Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter ... |
| CVE-2022-4416 | HIGH | 8.8 | 0.5% | Dec 12, 2022 | A vulnerability was found in RainyGao DocSys. It has been declared as critical. This vulnerability affects the function ... |
| CVE-2022-46908 | HIGH | 7.3 | 0.5% | Dec 12, 2022 | SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the ... |
| CVE-2022-25837 | HIGH | 7.5 | 0.4% | Dec 12, 2022 | Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire cred... |
| CVE-2022-25836 | HIGH | 7.5 | 0.4% | Dec 12, 2022 | Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to ac... |
| CVE-2022-45760 | HIGH | 8.8 | 0.6% | Dec 12, 2022 | SENS v1.0 is vulnerable to Incorrect Access Control vulnerability. |
| CVE-2022-45759 | HIGH | 8.8 | 0.6% | Dec 12, 2022 | SENS v1.0 has a file upload vulnerability. |
| CVE-2022-45227 | HIGH | 7.5 | 0.7% | Dec 12, 2022 | The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. Thi... |
| CVE-2022-4409 | HIGH | 7.5 | 0.4% | Dec 11, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9. |
| CVE-2022-4403 | HIGH | 8.8 | 0.6% | Dec 11, 2022 | A vulnerability classified as critical was found in SourceCodester Canteen Management System. This vulnerability affects... |
| CVE-2022-4402 | HIGH | 7.2 | 0.7% | Dec 11, 2022 | A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the co... |
| CVE-2022-4398 | HIGH | 7.8 | 0.3% | Dec 10, 2022 | Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5.8.0. |
| CVE-2022-23510 | HIGH | 8.8 | 0.9% | Dec 9, 2022 | cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL... |
| CVE-2022-23497 | HIGH | 7.5 | 0.8% | Dec 9, 2022 | FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition... |
| CVE-2022-46157 | HIGH | 8.8 | 1.4% | Dec 9, 2022 | Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119... |
| CVE-2022-44790 | HIGH | 7.5 | 0.6% | Dec 9, 2022 | Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could s... |
| CVE-2022-3724 | HIGH | 7.5 | 2.3% | Dec 9, 2022 | Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or cra... |
| CVE-2022-3259 | HIGH | 7.4 | 0.5% | Dec 9, 2022 | Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now