2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43755 | CRITICAL | 9.8 | 1.7% | Feb 7, 2023 | A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to conti... |
| CVE-2022-31249 | CRITICAL | 9.8 | 3.8% | Feb 7, 2023 | A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler o... |
| CVE-2022-3229 | CRITICAL | 9.8 | 66.4% | Feb 6, 2023 | Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication... |
| CVE-2022-48311 | CRITICAL | 9 | 1.0% | Feb 6, 2023 | **UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR... |
| CVE-2022-4681 | CRITICAL | 9.8 | 3.8% | Feb 6, 2023 | The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL ... |
| CVE-2022-47071 | CRITICAL | 9.8 | 25.9% | Feb 6, 2023 | In NVS365 V01, the background network test function can trigger command execution. |
| CVE-2022-48078 | CRITICAL | 9.8 | 0.9% | Feb 6, 2023 | pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component ASTre... |
| CVE-2022-31733 | CRITICAL | 9.1 | 0.4% | Feb 3, 2023 | Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are acc... |
| CVE-2022-48021 | CRITICAL | 9.8 | 0.9% | Feb 3, 2023 | A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message... |
| CVE-2022-38389 | CRITICAL | 9.1 | 1.3% | Feb 3, 2023 | IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when pro... |
| CVE-2022-22486 | CRITICAL | 9.1 | 1.4% | Feb 3, 2023 | IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when pro... |
| CVE-2022-48114 | CRITICAL | 9.8 | 0.9% | Feb 2, 2023 | RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable. |
| CVE-2022-48113 | CRITICAL | 9.8 | 0.9% | Feb 2, 2023 | A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet servic... |
| CVE-2022-48130 | CRITICAL | 9.8 | 0.9% | Feb 2, 2023 | Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the para... |
| CVE-2022-48082 | CRITICAL | 9.8 | 0.6% | Feb 2, 2023 | Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.as... |
| CVE-2022-48079 | CRITICAL | 9.8 | 1.4% | Feb 2, 2023 | Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execu... |
| CVE-2022-47714 | CRITICAL | 9.8 | 0.6% | Feb 1, 2023 | Last Yard 22.09.8-1 does not enforce HSTS headers |
| CVE-2022-47003 | CRITICAL | 9.8 | 3.6% | Feb 1, 2023 | A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a... |
| CVE-2022-47002 | CRITICAL | 9.8 | 6.3% | Feb 1, 2023 | A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authenticatio... |
| CVE-2022-45100 | CRITICAL | 9.8 | 0.5% | Feb 1, 2023 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unaut... |
| CVE-2022-45101 | CRITICAL | 9.8 | 0.8% | Feb 1, 2023 | Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS.... |
| CVE-2022-42971 | CRITICAL | 9.8 | 1.1% | Feb 1, 2023 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution w... |
| CVE-2022-42970 | CRITICAL | 9.8 | 0.7% | Feb 1, 2023 | A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionali... |
| CVE-2022-2329 | CRITICAL | 9.8 | 2.1% | Feb 1, 2023 | A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to d... |
| CVE-2022-24324 | CRITICAL | 9.8 | 1.2% | Feb 1, 2023 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflo... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now