2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34125 | MEDIUM | 6.5 | 4.6% | Apr 16, 2023 | front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive informati... |
| CVE-2022-30076 | MEDIUM | 5.3 | 3.5% | Apr 16, 2023 | ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames... |
| CVE-2022-28353 | MEDIUM | 6.1 | 0.6% | Apr 16, 2023 | In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS. |
| CVE-2022-43128 | — | — | — | Apr 16, 2023 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2022-42245. Reason: This record is a duplicate of CVE-2022-... |
| CVE-2022-40946 | HIGH | 7.5 | 8.0% | Apr 16, 2023 | On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t... |
| CVE-2022-38841 | HIGH | 8.8 | 10.7% | Apr 16, 2023 | Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagn... |
| CVE-2022-38840 | HIGH | 7.5 | 9.8% | Apr 16, 2023 | cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file uplo... |
| CVE-2022-37306 | MEDIUM | 6.1 | 0.6% | Apr 16, 2023 | OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger. |
| CVE-2022-37255 | HIGH | 7.5 | 4.9% | Apr 16, 2023 | TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL07552646... |
| CVE-2022-37186 | MEDIUM | 5.9 | 0.7% | Apr 16, 2023 | In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the time... |
| CVE-2022-37705 | MEDIUM | 6.7 | 1.2% | Apr 16, 2023 | A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerab... |
| CVE-2022-37704 | MEDIUM | 6.7 | 0.5% | Apr 16, 2023 | Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/ru... |
| CVE-2022-2525 | CRITICAL | 9.8 | 0.8% | Apr 15, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. |
| CVE-2022-47522 | HIGH | 7.5 | 0.9% | Apr 15, 2023 | The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) t... |
| CVE-2022-45030 | HIGH | 8.8 | 2.7% | Apr 15, 2023 | A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may... |
| CVE-2022-43699 | MEDIUM | 4.3 | 0.5% | Apr 15, 2023 | OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be a... |
| CVE-2022-43698 | MEDIUM | 4.3 | 0.5% | Apr 15, 2023 | OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list. |
| CVE-2022-43697 | MEDIUM | 6.1 | 0.4% | Apr 15, 2023 | OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob. |
| CVE-2022-43696 | MEDIUM | 6.1 | 0.4% | Apr 15, 2023 | OX App Suite before 7.10.6-rev20 allows XSS via upsell ads. |
| CVE-2022-48178 | MEDIUM | 5.4 | 1.8% | Apr 15, 2023 | X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via ... |
| CVE-2022-48177 | MEDIUM | 5.4 | 1.8% | Apr 15, 2023 | X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v... |
| CVE-2022-46886 | MEDIUM | 6.1 | 0.3% | Apr 14, 2023 | There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redi... |
| CVE-2022-47501 | HIGH | 7.5 | 10.2% | Apr 14, 2023 | Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a p... |
| CVE-2022-4893 | — | — | — | Apr 14, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3748 | CRITICAL | 9.8 | 0.9% | Apr 14, 2023 | Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affect... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now