2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20962 | HIGH | 8.8 | 1.0% | Nov 4, 2022 | A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated... |
| CVE-2022-20961 | HIGH | 8.8 | 0.4% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic... |
| CVE-2022-20960 | HIGH | 7.5 | 0.8% | Nov 4, 2022 | A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote... |
| CVE-2022-20958 | HIGH | 8.8 | 0.9% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthent... |
| CVE-2022-20956 | HIGH | 8.8 | 1.3% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2022-20868 | HIGH | 8.8 | 0.7% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Mana... |
| CVE-2022-41671 | HIGH | 7.8 | 0.3% | Nov 4, 2022 | A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that al... |
| CVE-2022-41670 | HIGH | 7.8 | 0.2% | Nov 4, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGI... |
| CVE-2022-41669 | HIGH | 7.8 | 0.1% | Nov 4, 2022 | A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows... |
| CVE-2022-41668 | HIGH | 7.8 | 0.2% | Nov 4, 2022 | A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load ... |
| CVE-2022-41667 | HIGH | 7.8 | 0.2% | Nov 4, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allow... |
| CVE-2022-3340 | HIGH | 7.2 | 0.5% | Nov 4, 2022 | XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administra... |
| CVE-2022-33684 | HIGH | 8.1 | 0.7% | Nov 4, 2022 | The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Crede... |
| CVE-2022-41666 | HIGH | 7.8 | 0.1% | Nov 4, 2022 | A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user... |
| CVE-2022-43571 | HIGH | 8.8 | 14.3% | Nov 3, 2022 | In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through t... |
| CVE-2022-43574 | HIGH | 7.5 | 0.5% | Nov 3, 2022 | "IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignm... |
| CVE-2022-43495 | HIGH | 7.5 | 0.6% | Nov 3, 2022 | OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a netwo... |
| CVE-2022-43063 | HIGH | 7.2 | 0.7% | Nov 3, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-43062 | HIGH | 7.2 | 0.7% | Nov 3, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-43061 | HIGH | 7.2 | 0.9% | Nov 3, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the co... |
| CVE-2022-42745 | HIGH | 7.5 | 0.8% | Nov 3, 2022 | CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because th... |
| CVE-2022-35717 | HIGH | 7.8 | 0.6% | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on th... |
| CVE-2022-30608 | HIGH | 8.8 | 0.3% | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exe... |
| CVE-2022-25952 | HIGH | 8.8 | 0.3% | Nov 3, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress. |
| CVE-2022-3258 | HIGH | 8.8 | 0.2% | Nov 3, 2022 | Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentic... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now