2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44942 | HIGH | 8.1 | 0.9% | Dec 7, 2022 | Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function. |
| CVE-2022-45915 | HIGH | 8.8 | 4.7% | Dec 7, 2022 | ILIAS before 7.16 allows OS Command Injection. |
| CVE-2022-44030 | HIGH | 7.5 | 0.6% | Dec 6, 2022 | Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permis... |
| CVE-2022-42699 | HIGH | 8.8 | 1.3% | Dec 6, 2022 | Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. |
| CVE-2022-45829 | HIGH | 8.1 | 0.8% | Dec 6, 2022 | Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress. |
| CVE-2022-42888 | HIGH | 8.8 | 0.7% | Dec 6, 2022 | Unauth. Privilege Escalation vulnerability in ARMember premium plugin <= 5.5.1 on WordPress. |
| CVE-2022-46333 | HIGH | 7.2 | 1.5% | Dec 6, 2022 | The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that e... |
| CVE-2022-23475 | HIGH | 8.8 | 0.5% | Dec 6, 2022 | daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination... |
| CVE-2022-4147 | HIGH | 7.5 | 0.6% | Dec 6, 2022 | Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made... |
| CVE-2022-46154 | HIGH | 7.5 | 0.8% | Dec 6, 2022 | Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not p... |
| CVE-2022-45548 | HIGH | 8.8 | 0.8% | Dec 6, 2022 | AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability. |
| CVE-2022-43867 | HIGH | 7.8 | 0.3% | Dec 6, 2022 | IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container.... |
| CVE-2022-34361 | HIGH | 7.5 | 0.4% | Dec 6, 2022 | IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decr... |
| CVE-2022-23472 | HIGH | 7.5 | 0.8% | Dec 6, 2022 | Passeo is an open source python password generator. Versions prior to 1.0.5 rely on the python `random` library for rand... |
| CVE-2022-23470 | HIGH | 7.5 | 0.8% | Dec 6, 2022 | Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due ... |
| CVE-2022-33875 | HIGH | 8.8 | 0.7% | Dec 6, 2022 | An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiA... |
| CVE-2022-30305 | HIGH | 7.5 | 0.6% | Dec 6, 2022 | An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1... |
| CVE-2022-46382 | HIGH | 8.8 | 0.6% | Dec 6, 2022 | RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 h... |
| CVE-2022-44289 | HIGH | 8.8 | 2.9% | Dec 6, 2022 | Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell. |
| CVE-2022-41325 | HIGH | 7.8 | 0.6% | Dec 6, 2022 | An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user... |
| CVE-2022-38123 | HIGH | 7.2 | 0.7% | Dec 6, 2022 | Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrato... |
| CVE-2022-4300 | HIGH | 8.8 | 0.8% | Dec 6, 2022 | A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the f... |
| CVE-2022-42778 | HIGH | 7.8 | 0.1% | Dec 6, 2022 | In windows manager service, there is a missing permission check. This could lead to set up windows manager service with ... |
| CVE-2022-42777 | HIGH | 7.8 | 0.1% | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service wit... |
| CVE-2022-42776 | HIGH | 7.8 | 0.1% | Dec 6, 2022 | In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no addit... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now