2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2948 | HIGH | 7.8 | 0.2% | Dec 7, 2022 | GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to e... |
| CVE-2022-2002 | HIGH | 7.8 | 0.3% | Dec 7, 2022 | GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gm... |
| CVE-2022-23491 | HIGH | 7.5 | 0.5% | Dec 7, 2022 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verify... |
| CVE-2022-23487 | HIGH | 7.5 | 0.7% | Dec 7, 2022 | js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp... |
| CVE-2022-23486 | HIGH | 7.5 | 0.7% | Dec 7, 2022 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an ... |
| CVE-2022-46770 | HIGH | 7.5 | 21.5% | Dec 7, 2022 | qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of s... |
| CVE-2022-44373 | HIGH | 8.8 | 1.4% | Dec 7, 2022 | A stack overflow vulnerability exists in TrendNet Wireless AC Easy-Upgrader TEW-820AP (Version v1.0R, firmware version 1... |
| CVE-2022-43581 | HIGH | 8.8 | 0.7% | Dec 7, 2022 | IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 i... |
| CVE-2022-44393 | HIGH | 7.2 | 0.8% | Dec 7, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=. |
| CVE-2022-41720 | HIGH | 7.5 | 1.2% | Dec 7, 2022 | On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide ... |
| CVE-2022-40966 | HIGH | 8.8 | 0.3% | Dec 7, 2022 | Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass aut... |
| CVE-2022-4322 | HIGH | 7.2 | 0.8% | Dec 7, 2022 | A vulnerability, which was classified as critical, was found in maku-boot up to 2.2.0. This affects the function doExecu... |
| CVE-2022-44620 | HIGH | 8.8 | 0.9% | Dec 7, 2022 | Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earli... |
| CVE-2022-44608 | HIGH | 7.5 | 0.9% | Dec 7, 2022 | Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated at... |
| CVE-2022-44606 | HIGH | 8.8 | 1.5% | Dec 7, 2022 | OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier ... |
| CVE-2022-43667 | HIGH | 7.8 | 0.3% | Dec 7, 2022 | Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disc... |
| CVE-2022-43660 | HIGH | 7.2 | 1.0% | Dec 7, 2022 | Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authentic... |
| CVE-2022-43509 | HIGH | 7.8 | 0.2% | Dec 7, 2022 | Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure a... |
| CVE-2022-43508 | HIGH | 7.8 | 0.2% | Dec 7, 2022 | Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or... |
| CVE-2022-43468 | HIGH | 7.5 | 0.8% | Dec 7, 2022 | External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and ea... |
| CVE-2022-43464 | HIGH | 8.8 | 1.0% | Dec 7, 2022 | Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier ... |
| CVE-2022-41800 | HIGH | 8.7 | 62.4% | Dec 7, 2022 | In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be... |
| CVE-2022-41622 | HIGH | 8.8 | 88.0% | Dec 7, 2022 | In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. ... |
| CVE-2022-44849 | HIGH | 8.8 | 0.4% | Dec 7, 2022 | A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super ... |
| CVE-2022-45009 | HIGH | 7.2 | 1.0% | Dec 7, 2022 | Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/cl... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now