2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46869 | HIGH | 7.8 | 0.2% | Aug 31, 2023 | Local privilege escalation during installation due to improper soft link handling. The following products are affected: ... |
| CVE-2022-40214 | — | — | — | Aug 31, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2022-46868 | HIGH | 7.8 | 0.2% | Aug 31, 2023 | Local privilege escalation during recovery due to improper soft link handling. The following products are affected: Acro... |
| CVE-2022-45451 | HIGH | 7.8 | 0.5% | Aug 31, 2023 | Local privilege escalation due to insecure driver communication port permissions. The following products are affected: A... |
| CVE-2022-1601 | MEDIUM | 5.3 | 0.6% | Aug 30, 2023 | The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from certain HTTP headers over... |
| CVE-2022-46783 | MEDIUM | 5.3 | 0.2% | Aug 28, 2023 | An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may ... |
| CVE-2022-43904 | HIGH | 7.5 | 0.7% | Aug 28, 2023 | IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of e... |
| CVE-2022-43909 | MEDIUM | 5.4 | 0.3% | Aug 27, 2023 | IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2022-43907 | HIGH | 8.8 | 1.0% | Aug 27, 2023 | IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by se... |
| CVE-2022-4452 | HIGH | 8.8 | 0.4% | Aug 25, 2023 | Insufficient data validation in crosvm in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially ... |
| CVE-2022-46884 | HIGH | 8.8 | 0.4% | Aug 24, 2023 | A potential use-after-free vulnerability existed in SVG Images if the Refresh Driver was destroyed at an inopportune tim... |
| CVE-2022-3746 | MEDIUM | 6.7 | 0.2% | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local ... |
| CVE-2022-3745 | MEDIUM | 4.4 | 0.2% | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local ... |
| CVE-2022-3744 | MEDIUM | 6.7 | 0.2% | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local ... |
| CVE-2022-3743 | MEDIUM | 4.4 | 0.2% | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local ... |
| CVE-2022-3742 | MEDIUM | 6.7 | 0.2% | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local ... |
| CVE-2022-48571 | HIGH | 7.5 | 0.9% | Aug 22, 2023 | memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP. |
| CVE-2022-48570 | HIGH | 7.5 | 0.8% | Aug 22, 2023 | Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanu... |
| CVE-2022-48566 | MEDIUM | 5.9 | 1.1% | Aug 22, 2023 | An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations ... |
| CVE-2022-48565 | CRITICAL | 9.8 | 4.3% | Aug 22, 2023 | An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity ... |
| CVE-2022-48564 | MEDIUM | 6.5 | 1.4% | Aug 22, 2023 | read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when... |
| CVE-2022-48560 | HIGH | 7.5 | 1.8% | Aug 22, 2023 | A use-after-free exists in Python through 3.9 via heappushpop in heapq. |
| CVE-2022-48554 | MEDIUM | 5.5 | 0.7% | Aug 22, 2023 | File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Sou... |
| CVE-2022-48547 | MEDIUM | 6.1 | 0.7% | Aug 22, 2023 | A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers... |
| CVE-2022-48545 | MEDIUM | 5.5 | 0.2% | Aug 22, 2023 | An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now