2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4955 | MEDIUM | 6.5 | 0.3% | Aug 4, 2023 | Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a use... |
| CVE-2022-41401 | MEDIUM | 6.5 | 1.2% | Aug 4, 2023 | OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to ex... |
| CVE-2022-42986 | — | — | — | Aug 3, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-39122. Reason: This candidate is a reservation d... |
| CVE-2022-26838 | MEDIUM | 6.5 | 1.0% | Aug 3, 2023 | Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticate... |
| CVE-2022-4046 | HIGH | 8.8 | 0.7% | Aug 3, 2023 | In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow ... |
| CVE-2022-34453 | HIGH | 7.1 | 0.4% | Aug 3, 2023 | Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only use... |
| CVE-2022-46484 | HIGH | 7.5 | 0.7% | Aug 2, 2023 | Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and bel... |
| CVE-2022-40609 | CRITICAL | 9.8 | 1.8% | Aug 2, 2023 | IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the sys... |
| CVE-2022-46485 | HIGH | 7.5 | 1.0% | Aug 2, 2023 | Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey... |
| CVE-2022-2416 | MEDIUM | 4.3 | 0.3% | Aug 2, 2023 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enu... |
| CVE-2022-2346 | MEDIUM | 4.3 | 0.3% | Aug 2, 2023 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoin... |
| CVE-2022-39987 | HIGH | 8.8 | 34.7% | Aug 1, 2023 | A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS co... |
| CVE-2022-39986 | CRITICAL | 9.8 | 98.7% | Aug 1, 2023 | A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary comma... |
| CVE-2022-42183 | CRITICAL | 9.1 | 0.7% | Jul 31, 2023 | Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Server-Side Request Forgery (SSRF). |
| CVE-2022-42182 | MEDIUM | 5.3 | 0.9% | Jul 31, 2023 | Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Directory Traversal. |
| CVE-2022-4888 | MEDIUM | 6.5 | 0.3% | Jul 31, 2023 | The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom... |
| CVE-2022-43831 | HIGH | 7.8 | 0.2% | Jul 31, 2023 | IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.6.1 could allow a local user to obtain escalated p... |
| CVE-2022-4926 | MEDIUM | 6.5 | 0.5% | Jul 29, 2023 | Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker... |
| CVE-2022-4925 | MEDIUM | 6.5 | 0.5% | Jul 29, 2023 | Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to p... |
| CVE-2022-4924 | CRITICAL | 9.6 | 0.5% | Jul 29, 2023 | Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the render... |
| CVE-2022-4923 | LOW | 3.1 | 0.2% | Jul 29, 2023 | Inappropriate implementation in Omnibox in Google Chrome prior to 99.0.4844.51 allowed an attacker in a privileged netwo... |
| CVE-2022-4922 | MEDIUM | 6.5 | 0.5% | Jul 29, 2023 | Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spo... |
| CVE-2022-4921 | HIGH | 8.8 | 0.5% | Jul 29, 2023 | Use after free in Accessibility in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to... |
| CVE-2022-4920 | CRITICAL | 9.6 | 0.6% | Jul 29, 2023 | Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to ... |
| CVE-2022-4919 | HIGH | 8.8 | 0.5% | Jul 29, 2023 | Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now