2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3843 | CRITICAL | 9.1 | 0.9% | Feb 16, 2023 | In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without author... |
| CVE-2022-43969 | CRITICAL | 9.1 | 0.5% | Feb 16, 2023 | Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials. |
| CVE-2022-46892 | CRITICAL | 9.8 | 0.6% | Feb 15, 2023 | In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root... |
| CVE-2022-47034 | CRITICAL | 9.8 | 0.8% | Feb 13, 2023 | A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass aut... |
| CVE-2022-3089 | CRITICAL | 9.8 | 0.3% | Feb 13, 2023 | Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker... |
| CVE-2022-4445 | CRITICAL | 9.8 | 1.1% | Feb 13, 2023 | The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2022-40022 | CRITICAL | 9.8 | 92.5% | Feb 13, 2023 | Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. |
| CVE-2022-48323 | CRITICAL | 9.8 | 56.8% | Feb 13, 2023 | Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A... |
| CVE-2022-48322 | CRITICAL | 9.8 | 0.7% | Feb 13, 2023 | NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affect... |
| CVE-2022-4557 | CRITICAL | 9.8 | 0.7% | Feb 12, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy ... |
| CVE-2022-45088 | CRITICAL | 9.8 | 0.7% | Feb 12, 2023 | Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File In... |
| CVE-2022-41731 | CRITICAL | 9.8 | 0.9% | Feb 12, 2023 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send sp... |
| CVE-2022-40514 | CRITICAL | 9.8 | 0.5% | Feb 12, 2023 | Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in rea... |
| CVE-2022-33279 | CRITICAL | 9.8 | 0.4% | Feb 12, 2023 | Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length. |
| CVE-2022-25729 | CRITICAL | 9.8 | 0.4% | Feb 12, 2023 | Memory corruption in modem due to improper length check while copying into memory |
| CVE-2022-45766 | CRITICAL | 9.1 | 0.8% | Feb 10, 2023 | Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Mana... |
| CVE-2022-43501 | CRITICAL | 9.1 | 0.6% | Feb 10, 2023 | KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insuffic... |
| CVE-2022-45699 | CRITICAL | 9.8 | 76.6% | Feb 10, 2023 | Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attack... |
| CVE-2022-43550 | CRITICAL | 9.8 | 1.8% | Feb 9, 2023 | A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching ... |
| CVE-2022-48290 | CRITICAL | 9.1 | 0.4% | Feb 9, 2023 | The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may af... |
| CVE-2022-45982 | CRITICAL | 9.8 | 1.2% | Feb 8, 2023 | thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to e... |
| CVE-2022-45527 | CRITICAL | 9.8 | 0.9% | Feb 8, 2023 | File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to d... |
| CVE-2022-45526 | CRITICAL | 9.8 | 1.0% | Feb 8, 2023 | SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbi... |
| CVE-2022-43764 | CRITICAL | 9.8 | 0.8% | Feb 8, 2023 | Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07... |
| CVE-2022-43762 | CRITICAL | 9.8 | 0.6% | Feb 8, 2023 | Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now