2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43590 | MEDIUM | 5.5 | 0.3% | Nov 28, 2022 | A null pointer dereference vulnerability exists in the handle_ioctl_0x830a0_systembuffer functionality of Callback techn... |
| CVE-2022-43589 | MEDIUM | 5.5 | 0.3% | Nov 28, 2022 | A null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Fi... |
| CVE-2022-43588 | MEDIUM | 5.5 | 0.3% | Nov 28, 2022 | A null pointer dereference vulnerability exists in the handle_ioctl_83150 functionality of Callback technologies CBFS Fi... |
| CVE-2022-45914 | MEDIUM | 6.5 | 0.7% | Nov 27, 2022 | The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-21... |
| CVE-2022-45225 | MEDIUM | 6.1 | 0.5% | Nov 25, 2022 | Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index... |
| CVE-2022-39333 | MEDIUM | 6.1 | 0.9% | Nov 25, 2022 | Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in... |
| CVE-2022-39332 | MEDIUM | 5.4 | 0.9% | Nov 25, 2022 | Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in... |
| CVE-2022-39325 | MEDIUM | 6.1 | 0.5% | Nov 25, 2022 | BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scrip... |
| CVE-2022-41926 | MEDIUM | 5.5 | 0.3% | Nov 25, 2022 | Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the rece... |
| CVE-2022-39346 | MEDIUM | 6.5 | 1.0% | Nov 25, 2022 | Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit u... |
| CVE-2022-39339 | MEDIUM | 4.3 | 0.4% | Nov 25, 2022 | user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the ... |
| CVE-2022-39338 | MEDIUM | 5.4 | 0.6% | Nov 25, 2022 | user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery u... |
| CVE-2022-39334 | MEDIUM | 4.7 | 0.2% | Nov 25, 2022 | Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless serv... |
| CVE-2022-39331 | MEDIUM | 5.4 | 0.9% | Nov 25, 2022 | Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in... |
| CVE-2022-45475 | MEDIUM | 6.5 | 0.8% | Nov 25, 2022 | Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. Th... |
| CVE-2022-41712 | MEDIUM | 6.5 | 0.9% | Nov 25, 2022 | Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because th... |
| CVE-2022-0698 | MEDIUM | 6.1 | 0.7% | Nov 25, 2022 | Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' p... |
| CVE-2022-45218 | MEDIUM | 6.1 | 0.4% | Nov 25, 2022 | Human Resource Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. This vulne... |
| CVE-2022-45210 | MEDIUM | 4.3 | 0.5% | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin. |
| CVE-2022-45208 | MEDIUM | 4.3 | 0.5% | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin. |
| CVE-2022-45205 | MEDIUM | 5.3 | 0.6% | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. |
| CVE-2022-45040 | MEDIUM | 5.4 | 0.4% | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to exec... |
| CVE-2022-45038 | MEDIUM | 5.4 | 1.0% | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute ar... |
| CVE-2022-45037 | MEDIUM | 5.4 | 1.0% | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbi... |
| CVE-2022-45036 | MEDIUM | 5.4 | 0.5% | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now