2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3711 | MEDIUM | 4.3 | 0.7% | Dec 1, 2022 | A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in ... |
| CVE-2022-45050 | MEDIUM | 6.1 | 0.4% | Dec 1, 2022 | A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's br... |
| CVE-2022-4253 | MEDIUM | 5.4 | 0.4% | Dec 1, 2022 | A vulnerability was found in SourceCodester Canteen Management System. It has been declared as problematic. This vulnera... |
| CVE-2022-4252 | MEDIUM | 6.1 | 0.4% | Dec 1, 2022 | A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affec... |
| CVE-2022-4251 | MEDIUM | 5.4 | 0.4% | Dec 1, 2022 | A vulnerability was found in Movie Ticket Booking System and classified as problematic. Affected by this issue is some u... |
| CVE-2022-4250 | MEDIUM | 6.1 | 0.4% | Dec 1, 2022 | A vulnerability has been found in Movie Ticket Booking System and classified as problematic. Affected by this vulnerabil... |
| CVE-2022-4249 | MEDIUM | 6.1 | 0.4% | Dec 1, 2022 | A vulnerability, which was classified as problematic, was found in Movie Ticket Booking System. Affected is an unknown f... |
| CVE-2022-40849 | MEDIUM | 5.4 | 0.4% | Dec 1, 2022 | ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vul... |
| CVE-2022-40204 | MEDIUM | 5.4 | 0.3% | Dec 1, 2022 | A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via t... |
| CVE-2022-4234 | MEDIUM | 6.1 | 0.4% | Nov 30, 2022 | A vulnerability was found in SourceCodester Canteen Management System. It has been rated as problematic. This issue affe... |
| CVE-2022-46149 | MEDIUM | 5.4 | 0.9% | Nov 30, 2022 | Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.... |
| CVE-2022-1911 | MEDIUM | 5.3 | 0.6% | Nov 30, 2022 | Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated ... |
| CVE-2022-1606 | MEDIUM | 4.3 | 0.5% | Nov 30, 2022 | Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to rea... |
| CVE-2022-38803 | MEDIUM | 6.8 | 0.6% | Nov 30, 2022 | Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An ... |
| CVE-2022-38802 | MEDIUM | 6.2 | 0.6% | Nov 30, 2022 | Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual ... |
| CVE-2022-38801 | MEDIUM | 5.4 | 0.3% | Nov 30, 2022 | In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cr... |
| CVE-2022-22984 | MEDIUM | 6.3 | 3.0% | Nov 30, 2022 | The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.... |
| CVE-2022-4233 | MEDIUM | 6.1 | 0.3% | Nov 30, 2022 | A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as problematic. Affected b... |
| CVE-2022-4231 | MEDIUM | 5.4 | 0.4% | Nov 30, 2022 | A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue... |
| CVE-2022-3859 | MEDIUM | 6.7 | 0.2% | Nov 30, 2022 | An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This all... |
| CVE-2022-46338 | MEDIUM | 6.5 | 0.7% | Nov 30, 2022 | g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nod... |
| CVE-2022-45869 | MEDIUM | 5.5 | 0.3% | Nov 30, 2022 | A race condition in the x86 KVM subsystem in the Linux kernel through 6.1-rc6 allows guest OS users to cause a denial of... |
| CVE-2022-41413 | MEDIUM | 4.3 | 2.0% | Nov 30, 2022 | perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attack... |
| CVE-2022-4195 | MEDIUM | 4.3 | 0.5% | Nov 30, 2022 | Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to by... |
| CVE-2022-4189 | MEDIUM | 4.3 | 0.4% | Nov 30, 2022 | Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now