2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36231 | CRITICAL | 9.8 | 3.0% | Feb 23, 2023 | pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3. |
| CVE-2022-48342 | CRITICAL | 9.8 | 0.3% | Feb 23, 2023 | In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents. |
| CVE-2022-2504 | CRITICAL | 9.8 | 0.6% | Feb 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Softw... |
| CVE-2022-48149 | CRITICAL | 9.8 | 0.6% | Feb 22, 2023 | Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via ... |
| CVE-2022-45599 | CRITICAL | 9.8 | 1.0% | Feb 22, 2023 | Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, al... |
| CVE-2022-39983 | CRITICAL | 9.8 | 1.4% | Feb 22, 2023 | File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attack... |
| CVE-2022-41217 | CRITICAL | 9.8 | 0.7% | Feb 22, 2023 | Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malici... |
| CVE-2022-46637 | CRITICAL | 9.8 | 1.5% | Feb 21, 2023 | Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services. |
| CVE-2022-45677 | CRITICAL | 9.8 | 0.9% | Feb 21, 2023 | SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student... |
| CVE-2022-45564 | CRITICAL | 9.8 | 0.8% | Feb 21, 2023 | SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute... |
| CVE-2022-48337 | CRITICAL | 9.8 | 1.6% | Feb 20, 2023 | GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, ... |
| CVE-2022-48317 | CRITICAL | 9.8 | 0.5% | Feb 20, 2023 | Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 a... |
| CVE-2022-48329 | CRITICAL | 9.8 | 0.9% | Feb 20, 2023 | MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/Gala... |
| CVE-2022-48328 | CRITICAL | 9.8 | 1.3% | Feb 20, 2023 | app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_de... |
| CVE-2022-40021 | CRITICAL | 9.8 | 1.4% | Feb 17, 2023 | QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vuln... |
| CVE-2022-47986 | CRITICAL | 9.8 | 100.0% | Feb 17, 2023 | IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system,... |
| CVE-2022-40032 | CRITICAL | 9.8 | 20.7% | Feb 17, 2023 | SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' paramet... |
| CVE-2022-40347 | CRITICAL | 9.8 | 5.3% | Feb 17, 2023 | SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType... |
| CVE-2022-33964 | CRITICAL | 9.8 | 0.6% | Feb 16, 2023 | Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to pote... |
| CVE-2022-29514 | CRITICAL | 9.8 | 0.6% | Feb 16, 2023 | Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potent... |
| CVE-2022-26843 | CRITICAL | 9.8 | 0.5% | Feb 16, 2023 | Insufficient visual distinction of homoglyphs presented to user in the Intel(R) oneAPI DPC++/C++ Compiler before version... |
| CVE-2022-25987 | CRITICAL | 9.8 | 0.5% | Feb 16, 2023 | Improper handling of Unicode encoding in source code to be compiled by the Intel(R) C++ Compiler Classic before version ... |
| CVE-2022-39954 | CRITICAL | 9.1 | 0.5% | Feb 16, 2023 | An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC vers... |
| CVE-2022-39952 | CRITICAL | 9.8 | 99.8% | Feb 16, 2023 | A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8... |
| CVE-2022-38375 | CRITICAL | 9.8 | 1.1% | Feb 16, 2023 | An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 all... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now