2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4812 | MEDIUM | 6.5 | 0.6% | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4811 | MEDIUM | 5.4 | 0.6% | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/me... |
| CVE-2022-4810 | MEDIUM | 4.3 | 0.5% | Dec 28, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4807 | MEDIUM | 4.3 | 0.6% | Dec 28, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4806 | MEDIUM | 5.3 | 0.8% | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4805 | MEDIUM | 4.3 | 0.5% | Dec 28, 2022 | Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4804 | MEDIUM | 5.3 | 0.6% | Dec 28, 2022 | Improper Authorization in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4802 | MEDIUM | 5.4 | 0.6% | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4801 | MEDIUM | 5.3 | 0.7% | Dec 28, 2022 | Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4800 | MEDIUM | 6.5 | 0.6% | Dec 28, 2022 | Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4799 | MEDIUM | 6.5 | 0.8% | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4798 | MEDIUM | 5.3 | 0.7% | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4797 | MEDIUM | 4.3 | 0.7% | Dec 28, 2022 | Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-3922 | MEDIUM | 4.8 | 0.5% | Dec 28, 2022 | The Broken Link Checker WordPress plugin before 1.11.20 does not sanitise and escape some of its settings, which could a... |
| CVE-2022-46174 | MEDIUM | 4.2 | 0.6% | Dec 28, 2022 | efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the... |
| CVE-2022-46173 | MEDIUM | 6.5 | 0.7% | Dec 28, 2022 | Elrond-GO is a go implementation for the Elrond Network protocol. Versions prior to 1.3.50 are subject to a processing i... |
| CVE-2022-46172 | MEDIUM | 6.4 | 0.5% | Dec 28, 2022 | authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, an... |
| CVE-2022-3346 | MEDIUM | 6.5 | 0.2% | Dec 28, 2022 | DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for inv... |
| CVE-2022-23544 | MEDIUM | 6.1 | 1.6% | Dec 28, 2022 | MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testi... |
| CVE-2022-2582 | MEDIUM | 4.3 | 0.5% | Dec 27, 2022 | The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash... |
| CVE-2022-47968 | MEDIUM | 5.4 | 0.4% | Dec 27, 2022 | Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add applicat... |
| CVE-2022-45434 | MEDIUM | 5.9 | 0.7% | Dec 27, 2022 | Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. Af... |
| CVE-2022-45432 | MEDIUM | 5.3 | 0.7% | Dec 27, 2022 | Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall ac... |
| CVE-2022-45426 | MEDIUM | 6.5 | 0.6% | Dec 27, 2022 | Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of o... |
| CVE-2022-45424 | MEDIUM | 5.3 | 0.7% | Dec 27, 2022 | Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now