2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31766 | HIGH | 8.6 | 1.0% | Oct 11, 2022 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDC... |
| CVE-2022-31765 | HIGH | 8.8 | 0.9% | Oct 11, 2022 | Affected devices do not properly authorize the change password function of the web interface. This could allow low priv... |
| CVE-2022-41749 | HIGH | 7.8 | 0.2% | Oct 10, 2022 | An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privile... |
| CVE-2022-41747 | HIGH | 7.8 | 0.2% | Oct 10, 2022 | An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a... |
| CVE-2022-41745 | HIGH | 7 | 0.7% | Oct 10, 2022 | An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create a specially crafted... |
| CVE-2022-41744 | HIGH | 7 | 0.2% | Oct 10, 2022 | A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component coul... |
| CVE-2022-3154 | HIGH | 7.1 | 0.3% | Oct 10, 2022 | The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before ... |
| CVE-2022-39288 | HIGH | 7.5 | 59.2% | Oct 10, 2022 | fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of s... |
| CVE-2022-34425 | HIGH | 7.5 | 0.7% | Oct 10, 2022 | Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote atta... |
| CVE-2022-20920 | HIGH | 7.7 | 0.8% | Oct 10, 2022 | A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, ... |
| CVE-2022-20915 | HIGH | 7.4 | 0.3% | Oct 10, 2022 | A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Softw... |
| CVE-2022-20870 | HIGH | 8.6 | 0.8% | Oct 10, 2022 | A vulnerability in the egress MPLS packet processing function of Cisco IOS XE Software for Cisco Catalyst 3650, Catalyst... |
| CVE-2022-20837 | HIGH | 8.6 | 0.9% | Oct 10, 2022 | A vulnerability in the DNS application layer gateway (ALG) functionality that is used by Network Address Translation (NA... |
| CVE-2022-39292 | HIGH | 7.5 | 0.7% | Oct 10, 2022 | Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitiv... |
| CVE-2022-42725 | HIGH | 7.5 | 1.2% | Oct 10, 2022 | Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links. |
| CVE-2022-3436 | HIGH | 7.5 | 0.5% | Oct 9, 2022 | A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by t... |
| CVE-2022-36635 | HIGH | 8.8 | 16.6% | Oct 7, 2022 | ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do... |
| CVE-2022-39959 | HIGH | 7.8 | 0.6% | Oct 7, 2022 | Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini fol... |
| CVE-2022-41574 | HIGH | 7.5 | 0.6% | Oct 7, 2022 | An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups ... |
| CVE-2022-3276 | HIGH | 8.8 | 1.6% | Oct 7, 2022 | Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to explo... |
| CVE-2022-39289 | HIGH | 7.5 | 0.8% | Oct 7, 2022 | ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder AP... |
| CVE-2022-36634 | HIGH | 8.8 | 1.3% | Oct 7, 2022 | An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a c... |
| CVE-2022-32591 | HIGH | 7.5 | 0.6% | Oct 7, 2022 | In ril, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service w... |
| CVE-2022-32589 | HIGH | 7.5 | 0.6% | Oct 7, 2022 | In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to rem... |
| CVE-2022-26472 | HIGH | 7.8 | 0.1% | Oct 7, 2022 | In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now