2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44737 | HIGH | 8.8 | 0.3% | Nov 22, 2022 | Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plu... |
| CVE-2022-33012 | HIGH | 8.8 | 1.3% | Nov 22, 2022 | Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack. |
| CVE-2022-42098 | HIGH | 8.8 | 1.2% | Nov 22, 2022 | KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php. |
| CVE-2022-3910 | HIGH | 7.8 | 1.0% | Nov 22, 2022 | Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_ur... |
| CVE-2022-0222 | HIGH | 7.5 | 0.6% | Nov 22, 2022 | A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet commu... |
| CVE-2022-37301 | HIGH | 7.5 | 0.7% | Nov 22, 2022 | A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the contr... |
| CVE-2022-41131 | HIGH | 7.8 | 1.8% | Nov 22, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl... |
| CVE-2022-37931 | HIGH | 7.8 | 0.2% | Nov 22, 2022 | A vulnerability in NetBatch-Plus software allows unauthorized access to the application. HPE has provided a workaround... |
| CVE-2022-35407 | HIGH | 7.8 | 0.2% | Nov 22, 2022 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code... |
| CVE-2022-43685 | HIGH | 8.8 | 0.7% | Nov 22, 2022 | CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request.... |
| CVE-2022-41937 | HIGH | 8.1 | 0.7% | Nov 22, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application... |
| CVE-2022-41936 | HIGH | 7.5 | 0.7% | Nov 22, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modificati... |
| CVE-2022-30529 | HIGH | 7.2 | 1.0% | Nov 22, 2022 | File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers... |
| CVE-2022-44786 | HIGH | 7.5 | 0.7% | Nov 21, 2022 | An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any pag... |
| CVE-2022-44784 | HIGH | 8.8 | 1.0% | Nov 21, 2022 | An issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of service... |
| CVE-2022-3388 | HIGH | 7.8 | 0.3% | Nov 21, 2022 | An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An auth... |
| CVE-2022-44830 | HIGH | 7.8 | 0.6% | Nov 21, 2022 | Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the Firs... |
| CVE-2022-45422 | HIGH | 7.8 | 0.2% | Nov 21, 2022 | When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-H... |
| CVE-2022-45470 | HIGH | 7.5 | 1.2% | Nov 21, 2022 | missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Ha... |
| CVE-2022-44163 | HIGH | 7.5 | 0.8% | Nov 21, 2022 | Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function formSetMacFilterCfg. |
| CVE-2022-44158 | HIGH | 7.5 | 0.8% | Nov 21, 2022 | Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function via set_device_name. |
| CVE-2022-44156 | HIGH | 7.5 | 0.8% | Nov 21, 2022 | Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind. |
| CVE-2022-40129 | HIGH | 7.8 | 1.0% | Nov 21, 2022 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A s... |
| CVE-2022-38148 | HIGH | 8.8 | 0.7% | Nov 21, 2022 | Silverstripe silverstripe/framework through 4.11 allows SQL Injection. |
| CVE-2022-38097 | HIGH | 7.8 | 0.8% | Nov 21, 2022 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now