2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4091 | MEDIUM | 6.1 | 0.4% | Nov 25, 2022 | A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affec... |
| CVE-2022-45888 | MEDIUM | 6.4 | 0.7% | Nov 25, 2022 | An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use... |
| CVE-2022-45887 | MEDIUM | 4.7 | 0.3% | Nov 25, 2022 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak bec... |
| CVE-2022-29833 | MEDIUM | 6.5 | 1.0% | Nov 25, 2022 | Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and late... |
| CVE-2022-29832 | MEDIUM | 6.5 | 0.6% | Nov 25, 2022 | Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions... |
| CVE-2022-4089 | MEDIUM | 5.4 | 0.4% | Nov 24, 2022 | A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability aff... |
| CVE-2022-40976 | MEDIUM | 5.5 | 0.2% | Nov 24, 2022 | A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a z... |
| CVE-2022-40266 | MEDIUM | 6.5 | 0.8% | Nov 24, 2022 | Improper Input Validation vulnerability in Mitsubishi Electric GOT2000 Series GT27 model FTP server versions 01.39.000 a... |
| CVE-2022-45873 | MEDIUM | 5.5 | 0.3% | Nov 23, 2022 | systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long back... |
| CVE-2022-45280 | MEDIUM | 5.4 | 0.3% | Nov 23, 2022 | A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to exec... |
| CVE-2022-41933 | MEDIUM | 6.5 | 0.4% | Nov 23, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset... |
| CVE-2022-41932 | MEDIUM | 5.3 | 0.5% | Nov 23, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t... |
| CVE-2022-45866 | MEDIUM | 5.3 | 1.3% | Nov 23, 2022 | qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allow... |
| CVE-2022-41946 | MEDIUM | 5.5 | 0.5% | Nov 23, 2022 | pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStateme... |
| CVE-2022-41935 | MEDIUM | 4.3 | 0.8% | Nov 23, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users without t... |
| CVE-2022-41929 | MEDIUM | 4.9 | 0.7% | Nov 23, 2022 | org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorre... |
| CVE-2022-40772 | MEDIUM | 6.5 | 3.0% | Nov 23, 2022 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to a... |
| CVE-2022-40771 | MEDIUM | 4.9 | 3.5% | Nov 23, 2022 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads t... |
| CVE-2022-36111 | MEDIUM | 5.3 | 0.4% | Nov 23, 2022 | immudb is a database with built-in cryptographic proof and verification. In versions prior to 1.4.1, a malicious immudb ... |
| CVE-2022-38115 | MEDIUM | 5.3 | 0.7% | Nov 23, 2022 | Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT |
| CVE-2022-38114 | MEDIUM | 6.1 | 0.5% | Nov 23, 2022 | This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lea... |
| CVE-2022-38113 | MEDIUM | 5.3 | 0.7% | Nov 23, 2022 | This vulnerability discloses build and services versions in the server response header. |
| CVE-2022-35501 | MEDIUM | 5.4 | 0.5% | Nov 23, 2022 | Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the du... |
| CVE-2022-44280 | MEDIUM | 6.5 | 0.8% | Nov 23, 2022 | Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img. |
| CVE-2022-45151 | MEDIUM | 5.4 | 0.7% | Nov 23, 2022 | The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied dat... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now