2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-48435 | LOW | 3.3 | 0.2% | Apr 4, 2023 | In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file |
| CVE-2022-47870 | MEDIUM | 6.1 | 2.2% | Apr 4, 2023 | A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows r... |
| CVE-2022-41633 | HIGH | 8.8 | 0.2% | Apr 4, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration... |
| CVE-2022-4934 | HIGH | 7.2 | 1.8% | Apr 4, 2023 | A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 ... |
| CVE-2022-4771 | MEDIUM | 6.1 | 0.4% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malici... |
| CVE-2022-4770 | MEDIUM | 4.3 | 0.4% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the fu... |
| CVE-2022-4769 | MEDIUM | 4.3 | 0.4% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the ta... |
| CVE-2022-43941 | MEDIUM | 6.5 | 0.5% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly... |
| CVE-2022-43940 | HIGH | 8.8 | 0.6% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly... |
| CVE-2022-43939 | CRITICAL | 9.8 | 92.3% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security ... |
| CVE-2022-43938 | HIGH | 8.8 | 26.6% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a... |
| CVE-2022-43772 | MEDIUM | 6.5 | 0.4% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Dat... |
| CVE-2022-43771 | MEDIUM | 6.5 | 23.9% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Penta... |
| CVE-2022-3960 | MEDIUM | 6.3 | 0.5% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a... |
| CVE-2022-43773 | HIGH | 8.8 | 22.2% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed w... |
| CVE-2022-43769 | HIGH | 7.2 | 97.7% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain w... |
| CVE-2022-38072 | HIGH | 8.8 | 1.1% | Apr 3, 2023 | An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master ... |
| CVE-2022-36440 | HIGH | 7.5 | 1.6% | Apr 3, 2023 | A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can malic... |
| CVE-2022-38923 | CRITICAL | 9.8 | 1.1% | Apr 3, 2023 | BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' fi... |
| CVE-2022-38922 | CRITICAL | 9.8 | 1.0% | Apr 3, 2023 | BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'us... |
| CVE-2022-27665 | MEDIUM | 6.1 | 33.1% | Apr 3, 2023 | Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead ... |
| CVE-2022-42452 | MEDIUM | 5.4 | 0.3% | Apr 2, 2023 | HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to ... |
| CVE-2022-42447 | HIGH | 8.8 | 0.4% | Apr 2, 2023 | HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote a... |
| CVE-2022-3487 | — | — | — | Apr 2, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2022-47192 | HIGH | 8.8 | 1.3% | Mar 31, 2023 | Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now