2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41568 | HIGH | 7.5 | 0.6% | Nov 29, 2022 | LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat. |
| CVE-2022-40799 | HIGH | 8.8 | 31.3% | Nov 29, 2022 | Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS l... |
| CVE-2022-45202 | HIGH | 7.8 | 0.3% | Nov 29, 2022 | GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isom... |
| CVE-2022-44037 | HIGH | 8.8 | 0.6% | Nov 29, 2022 | An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V... |
| CVE-2022-41675 | HIGH | 8 | 0.9% | Nov 29, 2022 | A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server ... |
| CVE-2022-3088 | HIGH | 7.8 | 0.2% | Nov 28, 2022 | UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image:... |
| CVE-2022-24190 | HIGH | 7.5 | 0.7% | Nov 28, 2022 | The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The us... |
| CVE-2022-24188 | HIGH | 7.5 | 0.5% | Nov 28, 2022 | The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functional... |
| CVE-2022-24187 | HIGH | 7.5 | 0.7% | Nov 28, 2022 | The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object... |
| CVE-2022-45921 | HIGH | 7.5 | 0.7% | Nov 28, 2022 | FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. ... |
| CVE-2022-45442 | HIGH | 8.8 | 0.6% | Nov 28, 2022 | Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 befo... |
| CVE-2022-38140 | HIGH | 8.8 | 0.7% | Nov 28, 2022 | Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress. |
| CVE-2022-34654 | HIGH | 8.8 | 0.3% | Nov 28, 2022 | Cross-Site Request Forgery (CSRF) in Virgial Berveling's Manage Notification E-mails plugin <= 1.8.2 on WordPress. |
| CVE-2022-41957 | HIGH | 7.5 | 0.9% | Nov 28, 2022 | Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara... |
| CVE-2022-31877 | HIGH | 8.8 | 0.4% | Nov 28, 2022 | An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a c... |
| CVE-2022-3865 | HIGH | 8.8 | 1.1% | Nov 28, 2022 | The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ... |
| CVE-2022-3849 | HIGH | 8.8 | 1.1% | Nov 28, 2022 | The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ... |
| CVE-2022-3848 | HIGH | 8.8 | 1.1% | Nov 28, 2022 | The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ... |
| CVE-2022-3769 | HIGH | 8.8 | 1.1% | Nov 28, 2022 | The OWM Weather WordPress plugin before 5.6.9 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2022-3768 | HIGH | 8.8 | 3.7% | Nov 28, 2022 | The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in... |
| CVE-2022-3689 | HIGH | 7.2 | 1.8% | Nov 28, 2022 | The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL sta... |
| CVE-2022-3490 | HIGH | 7.2 | 1.1% | Nov 28, 2022 | The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provi... |
| CVE-2022-4020 | HIGH | 8.2 | 0.2% | Nov 28, 2022 | Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated pr... |
| CVE-2022-38900 | HIGH | 7.5 | 24.9% | Nov 28, 2022 | decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS. |
| CVE-2022-45939 | HIGH | 7.8 | 0.6% | Nov 28, 2022 | GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now