2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39067 | MEDIUM | 6.5 | 0.6% | Nov 22, 2022 | There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interf... |
| CVE-2022-41952 | MEDIUM | 5.3 | 0.8% | Nov 22, 2022 | Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs... |
| CVE-2022-41445 | MEDIUM | 4.8 | 1.0% | Nov 22, 2022 | A cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute... |
| CVE-2022-42097 | MEDIUM | 4.8 | 0.8% | Nov 22, 2022 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' . |
| CVE-2022-42094 | MEDIUM | 4.8 | 2.5% | Nov 22, 2022 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' c... |
| CVE-2022-38462 | MEDIUM | 6.1 | 0.5% | Nov 22, 2022 | Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build... |
| CVE-2022-2513 | MEDIUM | 5.5 | 0.1% | Nov 22, 2022 | A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage fun... |
| CVE-2022-40954 | MEDIUM | 5.5 | 1.4% | Nov 22, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl... |
| CVE-2022-45363 | MEDIUM | 5.4 | 0.4% | Nov 22, 2022 | Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress. |
| CVE-2022-4111 | MEDIUM | 6.5 | 0.8% | Nov 22, 2022 | Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile... |
| CVE-2022-41940 | MEDIUM | 6.5 | 1.9% | Nov 22, 2022 | Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc... |
| CVE-2022-41223 | MEDIUM | 6.8 | 10.6% | Nov 22, 2022 | The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to ... |
| CVE-2022-40765 | MEDIUM | 6.8 | 10.5% | Nov 22, 2022 | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authen... |
| CVE-2022-43709 | MEDIUM | 4.9 | 0.6% | Nov 22, 2022 | MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify... |
| CVE-2022-43708 | MEDIUM | 6.1 | 0.4% | Nov 22, 2022 | MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow atta... |
| CVE-2022-43707 | MEDIUM | 6.1 | 0.5% | Nov 22, 2022 | MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attacker... |
| CVE-2022-44788 | MEDIUM | 6.5 | 0.6% | Nov 21, 2022 | An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESS... |
| CVE-2022-44787 | MEDIUM | 6.1 | 0.4% | Nov 21, 2022 | An issue was discovered in Appalti & Contratti 9.12.2. The web applications are vulnerable to a Reflected Cross-Site Scr... |
| CVE-2022-42096 | MEDIUM | 4.8 | 2.0% | Nov 21, 2022 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content... |
| CVE-2022-4105 | MEDIUM | 5.4 | 0.5% | Nov 21, 2022 | A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a... |
| CVE-2022-43117 | MEDIUM | 5.4 | 0.8% | Nov 21, 2022 | Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scrip... |
| CVE-2022-40746 | MEDIUM | 6.7 | 0.3% | Nov 21, 2022 | IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execut... |
| CVE-2022-38755 | MEDIUM | 5.3 | 0.6% | Nov 21, 2022 | A vulnerability has been identified in Micro Focus Filr in versions prior to 4.3.1.1. The vulnerability could be exploit... |
| CVE-2022-35897 | MEDIUM | 6.8 | 0.4% | Nov 21, 2022 | An stack buffer overflow vulnerability leads to arbitrary code execution issue was discovered in Insyde InsydeH2O with k... |
| CVE-2022-40470 | MEDIUM | 4.8 | 0.6% | Nov 21, 2022 | Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now