2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-48605 | CRITICAL | 9.8 | 0.4% | Sep 25, 2023 | Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect co... |
| CVE-2022-3962 | MEDIUM | 4.3 | 0.7% | Sep 23, 2023 | A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when... |
| CVE-2022-4039 | CRITICAL | 9.8 | 0.8% | Sep 22, 2023 | A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured manage... |
| CVE-2022-3874 | CRITICAL | 9.1 | 2.2% | Sep 22, 2023 | A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the forem... |
| CVE-2022-3596 | HIGH | 7.5 | 1.1% | Sep 20, 2023 | An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect s... |
| CVE-2022-3916 | MEDIUM | 6.8 | 1.0% | Sep 20, 2023 | A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especi... |
| CVE-2022-1438 | MEDIUM | 4.8 | 0.7% | Sep 20, 2023 | A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, r... |
| CVE-2022-45448 | MEDIUM | 6.1 | 0.3% | Sep 20, 2023 | M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document craftin... |
| CVE-2022-45447 | MEDIUM | 6.5 | 0.7% | Sep 20, 2023 | M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerabilit... |
| CVE-2022-47562 | HIGH | 7.5 | 0.6% | Sep 20, 2023 | Vulnerability in the RCPbind service running on UDP port (111), allowing a remote attacker to create a denial of service... |
| CVE-2022-47561 | MEDIUM | 5.5 | 0.2% | Sep 20, 2023 | The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into... |
| CVE-2022-47560 | MEDIUM | 6.5 | 0.3% | Sep 20, 2023 | The lack of web request control on ekorCCP and ekorRCI devices allows a potential attacker to create custom requests to ... |
| CVE-2022-47559 | HIGH | 8.8 | 0.2% | Sep 19, 2023 | Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to e... |
| CVE-2022-47558 | CRITICAL | 9.8 | 0.5% | Sep 19, 2023 | Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of t... |
| CVE-2022-47557 | MEDIUM | 6.1 | 0.1% | Sep 19, 2023 | Vulnerability in ekorCCP and ekorRCI that could allow an attacker with access to the network where the device is located... |
| CVE-2022-47556 | MEDIUM | 6.5 | 0.5% | Sep 19, 2023 | Uncontrolled resource consumption in ekorRCI, allowing an attacker with low-privileged access to the web server to send ... |
| CVE-2022-47555 | HIGH | 8.8 | 1.0% | Sep 19, 2023 | Operating system command injection in ekorCCP and ekorRCI, which could allow an authenticated attacker to execute comman... |
| CVE-2022-47554 | HIGH | 7.5 | 0.5% | Sep 19, 2023 | Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical info... |
| CVE-2022-47553 | HIGH | 7.5 | 0.6% | Sep 19, 2023 | Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive i... |
| CVE-2022-28357 | CRITICAL | 9.8 | 1.0% | Sep 19, 2023 | NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action fro... |
| CVE-2022-3261 | HIGH | 7.5 | 0.3% | Sep 15, 2023 | A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack o... |
| CVE-2022-47848 | HIGH | 7.5 | 0.7% | Sep 15, 2023 | An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.1... |
| CVE-2022-38636 | — | — | — | Sep 15, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3466 | MEDIUM | 5.3 | 0.2% | Sep 15, 2023 | The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316... |
| CVE-2022-20917 | MEDIUM | 4.3 | 0.9% | Sep 15, 2023 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber coul... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now