2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26471 | HIGH | 7.8 | 0.1% | Oct 7, 2022 | In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local esca... |
| CVE-2022-42074 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=. |
| CVE-2022-42073 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=. |
| CVE-2022-41379 | HIGH | 7.2 | 0.9% | Oct 7, 2022 | An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Managemen... |
| CVE-2022-41378 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad... |
| CVE-2022-41377 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad... |
| CVE-2022-37893 | HIGH | 7.8 | 0.8% | Oct 7, 2022 | An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Su... |
| CVE-2022-42092 | HIGH | 7.2 | 1.5% | Oct 7, 2022 | Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Executi... |
| CVE-2022-41515 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at... |
| CVE-2022-41514 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at... |
| CVE-2022-41513 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-41512 | HIGH | 7.2 | 0.9% | Oct 7, 2022 | An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management Sys... |
| CVE-2022-22493 | HIGH | 8.8 | 0.3% | Oct 7, 2022 | IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by imp... |
| CVE-2022-22480 | HIGH | 7.5 | 0.7% | Oct 7, 2022 | IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could res... |
| CVE-2022-39871 | HIGH | 7.5 | 0.3% | Oct 7, 2022 | Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows atta... |
| CVE-2022-39870 | HIGH | 7.5 | 0.3% | Oct 7, 2022 | Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta... |
| CVE-2022-39869 | HIGH | 7.5 | 0.3% | Oct 7, 2022 | Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta... |
| CVE-2022-39868 | HIGH | 7.5 | 0.3% | Oct 7, 2022 | Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to ... |
| CVE-2022-39867 | HIGH | 7.5 | 0.3% | Oct 7, 2022 | Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta... |
| CVE-2022-39866 | HIGH | 7.5 | 0.3% | Oct 7, 2022 | Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attacke... |
| CVE-2022-39865 | HIGH | 7.5 | 0.3% | Oct 7, 2022 | Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attac... |
| CVE-2022-39864 | HIGH | 7.5 | 0.3% | Oct 7, 2022 | Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attacker... |
| CVE-2022-39858 | HIGH | 7.8 | 0.2% | Oct 7, 2022 | Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write a... |
| CVE-2022-39854 | HIGH | 7.8 | 0.1% | Oct 7, 2022 | Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory. |
| CVE-2022-39853 | HIGH | 7.8 | 0.1% | Oct 7, 2022 | A use after free vulnerability in perf-mgr driver prior to SMR Oct-2022 Release 1 allows attacker to cause memory access... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now