2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39852 | HIGH | 7.8 | 0.1% | Oct 7, 2022 | A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release ... |
| CVE-2022-33896 | HIGH | 7.8 | 0.5% | Oct 7, 2022 | A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based offi... |
| CVE-2022-3422 | HIGH | 7.5 | 0.8% | Oct 7, 2022 | Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when ... |
| CVE-2022-41672 | HIGH | 8.1 | 1.2% | Oct 7, 2022 | In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being... |
| CVE-2022-41355 | HIGH | 7.2 | 0.8% | Oct 6, 2022 | Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /lea... |
| CVE-2022-27810 | HIGH | 7.5 | 0.7% | Oct 6, 2022 | It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciousl... |
| CVE-2022-41528 | HIGH | 8.8 | 0.9% | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter... |
| CVE-2022-41527 | HIGH | 8.8 | 0.9% | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser para... |
| CVE-2022-41526 | HIGH | 8.8 | 0.9% | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter i... |
| CVE-2022-41524 | HIGH | 8.8 | 0.9% | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, a... |
| CVE-2022-41523 | HIGH | 8.8 | 0.9% | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parame... |
| CVE-2022-42457 | HIGH | 7.2 | 2.2% | Oct 6, 2022 | Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update... |
| CVE-2022-42250 | HIGH | 7.2 | 0.8% | Oct 6, 2022 | Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/inquiries/view_details.php?id=... |
| CVE-2022-42249 | HIGH | 7.2 | 0.9% | Oct 6, 2022 | Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=. |
| CVE-2022-42243 | HIGH | 7.2 | 0.9% | Oct 6, 2022 | Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/manage_storage.php?id... |
| CVE-2022-42242 | HIGH | 7.2 | 0.9% | Oct 6, 2022 | Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_booking. |
| CVE-2022-42241 | HIGH | 7.2 | 0.9% | Oct 6, 2022 | Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_message. |
| CVE-2022-41556 | HIGH | 7.5 | 2.7% | Oct 6, 2022 | A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exh... |
| CVE-2022-41521 | HIGH | 8.8 | 0.9% | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort pa... |
| CVE-2022-41520 | HIGH | 8.8 | 0.9% | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter... |
| CVE-2022-41517 | HIGH | 8.8 | 0.8% | Oct 6, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLangu... |
| CVE-2022-3389 | HIGH | 7.5 | 1.0% | Oct 6, 2022 | Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10. |
| CVE-2022-39280 | HIGH | 7.5 | 1.0% | Oct 6, 2022 | dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is vul... |
| CVE-2022-39273 | HIGH | 7.5 | 0.7% | Oct 6, 2022 | FlyteAdmin is the control plane for the data processing platform Flyte. Users who enable the default Flyte’s authorizati... |
| CVE-2022-39265 | HIGH | 7.2 | 2.2% | Oct 6, 2022 | MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mai... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now