2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3431 | HIGH | 7.8 | 0.2% | Oct 9, 2023 | A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that wa... |
| CVE-2022-35950 | MEDIUM | 4.8 | 0.4% | Oct 9, 2023 | OroCommerce is an open-source Business to Business Commerce application. In versions 4.1.0 through 4.1.13, 4.2.0 through... |
| CVE-2022-33160 | HIGH | 7.5 | 0.3% | Oct 6, 2023 | IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to de... |
| CVE-2022-34355 | MEDIUM | 5.5 | 0.2% | Oct 6, 2023 | IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitiv... |
| CVE-2022-47175 | HIGH | 8.8 | 0.2% | Oct 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in P Royal Royal Elementor Addons and Templates plugin <= 1.3.75 version... |
| CVE-2022-3248 | HIGH | 7.5 | 0.4% | Oct 5, 2023 | A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow ... |
| CVE-2022-4145 | MEDIUM | 5.3 | 0.6% | Oct 5, 2023 | A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to ... |
| CVE-2022-36277 | MEDIUM | 6.1 | 0.3% | Oct 4, 2023 | The 'sReferencia', 'sDescripcion', 'txtCodigo' and 'txtDescripcion' parameters, in the frmGestionStock.aspx and frmEditS... |
| CVE-2022-36276 | CRITICAL | 9.8 | 0.8% | Oct 4, 2023 | TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The expl... |
| CVE-2022-43906 | MEDIUM | 5.3 | 0.4% | Oct 4, 2023 | IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a se... |
| CVE-2022-4132 | MEDIUM | 5.9 | 0.7% | Oct 4, 2023 | A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if conf... |
| CVE-2022-22447 | HIGH | 7.5 | 0.4% | Oct 4, 2023 | IBM Disconnected Log Collector 1.0 through 1.8.2 is vulnerable to potential security misconfigurations that could disclo... |
| CVE-2022-47893 | CRITICAL | 9.8 | 1.2% | Oct 3, 2023 | There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a... |
| CVE-2022-47892 | HIGH | 7.5 | 0.5% | Oct 3, 2023 | All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensiti... |
| CVE-2022-47891 | HIGH | 8.8 | 0.6% | Oct 3, 2023 | All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrat... |
| CVE-2022-46841 | HIGH | 8.8 | 0.2% | Oct 3, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Oxygen Builder plugin <= 4.4 versions. |
| CVE-2022-4956 | HIGH | 7.8 | 0.4% | Sep 30, 2023 | A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part o... |
| CVE-2022-35908 | HIGH | 8.8 | 0.7% | Sep 29, 2023 | Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent. |
| CVE-2022-47187 | MEDIUM | 6.1 | 0.4% | Sep 28, 2023 | There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading,... |
| CVE-2022-47186 | CRITICAL | 9.1 | 0.6% | Sep 28, 2023 | There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/... |
| CVE-2022-48606 | HIGH | 7.5 | 0.4% | Sep 27, 2023 | Stability-related vulnerability in the binder background management and control module. Successful exploitation of this ... |
| CVE-2022-4318 | HIGH | 7.8 | 0.3% | Sep 25, 2023 | A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a speci... |
| CVE-2022-4245 | MEDIUM | 4.3 | 0.7% | Sep 25, 2023 | A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comme... |
| CVE-2022-4244 | HIGH | 7.5 | 1.3% | Sep 25, 2023 | A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files ... |
| CVE-2022-4137 | MEDIUM | 6.1 | 1.1% | Sep 25, 2023 | A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte ha... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now