2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43279 | HIGH | 7.2 | 0.9% | Nov 15, 2022 | LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/th... |
| CVE-2022-3377 | HIGH | 7.8 | 0.2% | Nov 15, 2022 | Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a ... |
| CVE-2022-38385 | HIGH | 8.1 | 0.5% | Nov 15, 2022 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitiv... |
| CVE-2022-30772 | HIGH | 8.2 | 0.2% | Nov 15, 2022 | Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memor... |
| CVE-2022-30771 | HIGH | 8.2 | 0.2% | Nov 15, 2022 | Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization ... |
| CVE-2022-30283 | HIGH | 7.5 | 0.1% | Nov 15, 2022 | In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in pro... |
| CVE-2022-29275 | HIGH | 8.2 | 0.2% | Nov 15, 2022 | In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM ... |
| CVE-2022-20947 | HIGH | 7.5 | 0.9% | Nov 15, 2022 | A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance (ASA) Software and F... |
| CVE-2022-20946 | HIGH | 7.5 | 0.9% | Nov 15, 2022 | A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defens... |
| CVE-2022-20926 | HIGH | 8.8 | 0.8% | Nov 15, 2022 | A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an a... |
| CVE-2022-20925 | HIGH | 7.2 | 0.8% | Nov 15, 2022 | A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an a... |
| CVE-2022-20918 | HIGH | 7.5 | 0.8% | Nov 15, 2022 | A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adapti... |
| CVE-2022-20854 | HIGH | 7.5 | 0.9% | Nov 15, 2022 | A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Thre... |
| CVE-2022-45391 | HIGH | 7.5 | 0.4% | Nov 15, 2022 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/T... |
| CVE-2022-45388 | HIGH | 7.5 | 1.1% | Nov 15, 2022 | Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allow... |
| CVE-2022-45385 | HIGH | 7.5 | 0.6% | Nov 15, 2022 | A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthe... |
| CVE-2022-45381 | HIGH | 8.1 | 1.3% | Nov 15, 2022 | Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and b... |
| CVE-2022-45379 | HIGH | 7.5 | 0.5% | Nov 15, 2022 | Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the ... |
| CVE-2022-38666 | HIGH | 7.5 | 0.4% | Nov 15, 2022 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificat... |
| CVE-2022-27895 | HIGH | 7.5 | 0.4% | Nov 15, 2022 | Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying l... |
| CVE-2022-3240 | HIGH | 8.8 | 0.6% | Nov 15, 2022 | The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including... |
| CVE-2022-40308 | HIGH | 7.5 | 1.2% | Nov 15, 2022 | If anonymous read enabled, it's possible to read the database file directly without logging in. |
| CVE-2022-3737 | HIGH | 7.8 | 0.2% | Nov 15, 2022 | In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to ... |
| CVE-2022-3480 | HIGH | 7.5 | 0.9% | Nov 15, 2022 | A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices be... |
| CVE-2022-3461 | HIGH | 7.8 | 0.2% | Nov 15, 2022 | In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now