2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2969 | HIGH | 7.5 | 2.3% | Dec 1, 2022 | Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname int... |
| CVE-2022-29837 | HIGH | 7.8 | 0.2% | Dec 1, 2022 | A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which c... |
| CVE-2022-37017 | HIGH | 7.5 | 1.1% | Dec 1, 2022 | Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Contr... |
| CVE-2022-28607 | HIGH | 7.5 | 0.8% | Dec 1, 2022 | An issue was discovered in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers t... |
| CVE-2022-4246 | HIGH | 7.5 | 0.7% | Dec 1, 2022 | A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the compone... |
| CVE-2022-45640 | HIGH | 7.5 | 1.0% | Dec 1, 2022 | Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local). |
| CVE-2022-45045 | HIGH | 8.8 | 1.2% | Dec 1, 2022 | Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C74311... |
| CVE-2022-40489 | HIGH | 8.8 | 0.3% | Dec 1, 2022 | ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrato... |
| CVE-2022-23746 | HIGH | 7.5 | 0.6% | Nov 30, 2022 | The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the por... |
| CVE-2022-44296 | HIGH | 7.2 | 0.7% | Nov 30, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/quotes/manage_remark.php?id=. |
| CVE-2022-44295 | HIGH | 7.2 | 0.7% | Nov 30, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=. |
| CVE-2022-44294 | HIGH | 7.2 | 0.7% | Nov 30, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/manage_service&id=. |
| CVE-2022-26366 | HIGH | 8.8 | 0.3% | Nov 30, 2022 | Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin <= 5.9 on WordPress. |
| CVE-2022-24441 | HIGH | 8.8 | 0.7% | Nov 30, 2022 | The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince... |
| CVE-2022-4228 | HIGH | 7.5 | 1.2% | Nov 30, 2022 | A vulnerability classified as problematic has been found in SourceCodester Book Store Management System 1.0. This affect... |
| CVE-2022-41412 | HIGH | 8.6 | 4.1% | Nov 30, 2022 | An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and exec... |
| CVE-2022-45337 | HIGH | 7.5 | 0.8% | Nov 30, 2022 | Tenda TX9 Pro v22.03.02.10 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind. |
| CVE-2022-45332 | HIGH | 7.8 | 0.3% | Nov 30, 2022 | LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at dec... |
| CVE-2022-45328 | HIGH | 7.2 | 0.7% | Nov 30, 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi... |
| CVE-2022-40265 | HIGH | 7.5 | 0.9% | Nov 30, 2022 | Improper Input Validation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series RJ71EN71 Firmware version ... |
| CVE-2022-4194 | HIGH | 8.8 | 0.6% | Nov 30, 2022 | Use after free in Accessibility in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit... |
| CVE-2022-4193 | HIGH | 8.8 | 0.7% | Nov 30, 2022 | Insufficient policy enforcement in File System API in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to ... |
| CVE-2022-4192 | HIGH | 8.8 | 0.8% | Nov 30, 2022 | Use after free in Live Caption in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to... |
| CVE-2022-4191 | HIGH | 8.8 | 0.6% | Nov 30, 2022 | Use after free in Sign-In in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to enga... |
| CVE-2022-4190 | HIGH | 8.8 | 0.7% | Nov 30, 2022 | Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass fi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now