2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41040 | HIGH | 8.8 | 99.9% | Oct 3, 2022 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2022-42004 | HIGH | 7.5 | 2.7% | Oct 2, 2022 | In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeseriali... |
| CVE-2022-42003 | HIGH | 7.5 | 2.8% | Oct 2, 2022 | In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of... |
| CVE-2022-39268 | HIGH | 8.1 | 0.4% | Sep 30, 2022 | ### Impact In a CSRF attack, an innocent end user is tricked by an attacker into submitting a web request that they did ... |
| CVE-2022-34429 | HIGH | 7.1 | 0.2% | Sep 30, 2022 | Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potential... |
| CVE-2022-40756 | HIGH | 8.8 | 0.7% | Sep 30, 2022 | If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update ... |
| CVE-2022-40341 | HIGH | 8.8 | 1.2% | Sep 30, 2022 | mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbit... |
| CVE-2022-20919 | HIGH | 7.5 | 1.0% | Sep 30, 2022 | A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Softw... |
| CVE-2022-20856 | HIGH | 7.5 | 1.1% | Sep 30, 2022 | A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Ci... |
| CVE-2022-20851 | HIGH | 7.2 | 0.9% | Sep 30, 2022 | A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform ... |
| CVE-2022-20850 | HIGH | 7.1 | 0.2% | Sep 30, 2022 | A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenti... |
| CVE-2022-20848 | HIGH | 7.5 | 0.9% | Sep 30, 2022 | A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Cataly... |
| CVE-2022-20847 | HIGH | 7.5 | 1.1% | Sep 30, 2022 | A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 ... |
| CVE-2022-20818 | HIGH | 7.8 | 0.6% | Sep 30, 2022 | Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevat... |
| CVE-2022-20775 | HIGH | 7.8 | 12.5% | Sep 30, 2022 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privil... |
| CVE-2022-41975 | HIGH | 7.8 | 0.2% | Sep 30, 2022 | RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI inst... |
| CVE-2022-41870 | HIGH | 7.2 | 1.2% | Sep 30, 2022 | AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app u... |
| CVE-2022-40313 | HIGH | 7.1 | 0.5% | Sep 30, 2022 | Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a ... |
| CVE-2022-40277 | HIGH | 7.8 | 0.5% | Sep 30, 2022 | Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link ... |
| CVE-2022-40274 | HIGH | 7.8 | 0.4% | Sep 30, 2022 | Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a m... |
| CVE-2022-36961 | HIGH | 8.8 | 75.2% | Sep 30, 2022 | A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this ... |
| CVE-2022-41440 | HIGH | 7.2 | 0.7% | Sep 30, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor... |
| CVE-2022-41439 | HIGH | 7.2 | 0.7% | Sep 30, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor... |
| CVE-2022-41437 | HIGH | 7.2 | 1.3% | Sep 30, 2022 | Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php... |
| CVE-2022-3371 | HIGH | 7.5 | 1.0% | Sep 30, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now