2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3321 | HIGH | 8.2 | 0.4% | Oct 28, 2022 | It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect... |
| CVE-2022-3733 | HIGH | 8.8 | 0.5% | Oct 28, 2022 | A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. This... |
| CVE-2022-3616 | HIGH | 7.5 | 0.4% | Oct 28, 2022 | Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequen... |
| CVE-2022-3379 | HIGH | 7.8 | 0.2% | Oct 27, 2022 | Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a ... |
| CVE-2022-3378 | HIGH | 7.8 | 0.2% | Oct 27, 2022 | Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a... |
| CVE-2022-41773 | HIGH | 8.8 | 7.9% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIA... |
| CVE-2022-41627 | HIGH | 7.6 | 0.1% | Oct 27, 2022 | The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encr... |
| CVE-2022-41133 | HIGH | 8.8 | 26.6% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_... |
| CVE-2022-40967 | HIGH | 8.8 | 7.7% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoT... |
| CVE-2022-43340 | HIGH | 8.8 | 0.4% | Oct 27, 2022 | A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and... |
| CVE-2022-39978 | HIGH | 7.2 | 1.1% | Oct 27, 2022 | Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in... |
| CVE-2022-39977 | HIGH | 7.2 | 1.1% | Oct 27, 2022 | Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in... |
| CVE-2022-0074 | HIGH | 8.8 | 1.2% | Oct 27, 2022 | Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Containe... |
| CVE-2022-0073 | HIGH | 8.8 | 8.7% | Oct 27, 2022 | Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dash... |
| CVE-2022-43366 | HIGH | 7.5 | 0.8% | Oct 27, 2022 | IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to access sensitive information via the checkLoginUser, at... |
| CVE-2022-43365 | HIGH | 7.5 | 0.8% | Oct 27, 2022 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a buffer overflow in the formSetDebugCfg function. This vulnerabi... |
| CVE-2022-43364 | HIGH | 7.5 | 0.7% | Oct 27, 2022 | An access control issue in the password reset page of IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to a... |
| CVE-2022-40875 | HIGH | 7.5 | 0.8% | Oct 27, 2022 | Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo. |
| CVE-2022-40874 | HIGH | 7.5 | 0.8% | Oct 27, 2022 | Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, whic... |
| CVE-2022-41996 | HIGH | 8.8 | 0.5% | Oct 27, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leadin... |
| CVE-2022-3725 | HIGH | 7.5 | 0.8% | Oct 27, 2022 | Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafte... |
| CVE-2022-38744 | HIGH | 7.5 | 1.1% | Oct 27, 2022 | An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service... |
| CVE-2022-3409 | HIGH | 7.5 | 0.6% | Oct 27, 2022 | A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified d... |
| CVE-2022-2809 | HIGH | 7.5 | 0.6% | Oct 27, 2022 | A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser c... |
| CVE-2022-25918 | HIGH | 7.5 | 1.2% | Oct 27, 2022 | The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now