2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23740 | HIGH | 8.8 | 1.1% | Nov 23, 2022 | CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterpri... |
| CVE-2022-44278 | HIGH | 7.2 | 0.7% | Nov 23, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=. |
| CVE-2022-44260 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the se... |
| CVE-2022-44259 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTim... |
| CVE-2022-44258 | HIGH | 8.8 | 2.3% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTra... |
| CVE-2022-44257 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setO... |
| CVE-2022-44256 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLangua... |
| CVE-2022-44254 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg... |
| CVE-2022-44253 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosi... |
| CVE-2022-42896 | HIGH | 8.8 | 2.0% | Nov 23, 2022 | There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_c... |
| CVE-2022-40770 | HIGH | 7.2 | 82.5% | Nov 23, 2022 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can ... |
| CVE-2022-36337 | HIGH | 8.2 | 0.2% | Nov 23, 2022 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the Me... |
| CVE-2022-34830 | HIGH | 7.5 | 0.5% | Nov 23, 2022 | An Arm product family through 2022-06-29 has a TOCTOU Race Condition that allows non-privileged user to make improper GP... |
| CVE-2022-37772 | HIGH | 7.5 | 1.2% | Nov 23, 2022 | Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose ... |
| CVE-2022-43751 | HIGH | 7.8 | 0.2% | Nov 23, 2022 | McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the u... |
| CVE-2022-40870 | HIGH | 8.1 | 1.0% | Nov 23, 2022 | The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnera... |
| CVE-2022-40303 | HIGH | 7.5 | 22.8% | Nov 23, 2022 | An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE par... |
| CVE-2022-45331 | HIGH | 7.5 | 0.8% | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnera... |
| CVE-2022-45330 | HIGH | 7.5 | 0.8% | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This... |
| CVE-2022-41919 | HIGH | 8.8 | 0.4% | Nov 22, 2022 | Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Ty... |
| CVE-2022-2791 | HIGH | 7.8 | 0.2% | Nov 22, 2022 | Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File w... |
| CVE-2022-41943 | HIGH | 7.2 | 0.9% | Nov 22, 2022 | sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver ... |
| CVE-2022-41942 | HIGH | 7.8 | 1.5% | Nov 22, 2022 | Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the... |
| CVE-2022-41950 | HIGH | 7.8 | 0.4% | Nov 22, 2022 | super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerabilit... |
| CVE-2022-39066 | HIGH | 8.8 | 26.5% | Nov 22, 2022 | There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phon... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now