2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42751 | HIGH | 8.8 | 0.4% | Nov 3, 2022 | CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because t... |
| CVE-2022-42750 | HIGH | 8.8 | 1.0% | Nov 3, 2022 | CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the... |
| CVE-2022-3776 | HIGH | 8.8 | 0.5% | Nov 3, 2022 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2022-44624 | HIGH | 7.5 | 0.5% | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained sp... |
| CVE-2022-44623 | HIGH | 7.5 | 0.5% | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner setting... |
| CVE-2022-39234 | HIGH | 8.8 | 0.4% | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr... |
| CVE-2022-32287 | HIGH | 7.5 | 1.6% | Nov 3, 2022 | A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows ... |
| CVE-2022-44638 | HIGH | 8.8 | 1.4% | Nov 3, 2022 | In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edge... |
| CVE-2022-3181 | HIGH | 7.5 | 0.7% | Nov 2, 2022 | An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malform... |
| CVE-2022-43068 | HIGH | 7.2 | 0.7% | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-43066 | HIGH | 7.2 | 0.8% | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-43227 | HIGH | 7.2 | 0.7% | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-43226 | HIGH | 8.8 | 0.8% | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-39356 | HIGH | 8.8 | 0.6% | Nov 2, 2022 | Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single em... |
| CVE-2022-41716 | HIGH | 7.5 | 0.8% | Nov 2, 2022 | Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.Sta... |
| CVE-2022-41551 | HIGH | 7.2 | 0.8% | Nov 2, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed... |
| CVE-2022-43995 | HIGH | 7.1 | 0.3% | Nov 2, 2022 | Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-boun... |
| CVE-2022-35842 | HIGH | 7.5 | 0.6% | Nov 2, 2022 | An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0,... |
| CVE-2022-33870 | HIGH | 7.8 | 0.4% | Nov 2, 2022 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpre... |
| CVE-2022-30307 | HIGH | 8.1 | 0.4% | Nov 2, 2022 | A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and belo... |
| CVE-2022-26122 | HIGH | 8.6 | 0.4% | Nov 2, 2022 | An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engin... |
| CVE-2022-26119 | HIGH | 7.8 | 0.2% | Nov 2, 2022 | A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to pe... |
| CVE-2022-3723 | HIGH | 8.8 | 6.8% | Nov 1, 2022 | Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2022-3659 | HIGH | 8.8 | 0.5% | Nov 1, 2022 | Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convi... |
| CVE-2022-3658 | HIGH | 8.8 | 0.4% | Nov 1, 2022 | Use after free in Feedback service on Chrome OS in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed an attacker... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now