2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45597 | CRITICAL | 9.8 | 0.7% | Mar 24, 2023 | ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability b... |
| CVE-2022-42528 | MEDIUM | 5.5 | 0.1% | Mar 24, 2023 | In ffa_mrd_prot of shared_mem.c, there is a possible ID due to a logic error in the code. This could lead to local infor... |
| CVE-2022-42500 | MEDIUM | 6.7 | 0.1% | Mar 24, 2023 | In OEM_OnRequest of sced.cpp, there is a possible shell command execution due to improper input validation. This could l... |
| CVE-2022-42499 | CRITICAL | 9.8 | 0.5% | Mar 24, 2023 | In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. T... |
| CVE-2022-42498 | CRITICAL | 9.8 | 0.5% | Mar 24, 2023 | In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to re... |
| CVE-2022-40208 | MEDIUM | 4.3 | 0.6% | Mar 24, 2023 | In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigat... |
| CVE-2022-20542 | HIGH | 7.8 | 0.1% | Mar 24, 2023 | In parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead ... |
| CVE-2022-20532 | CRITICAL | 9.8 | 0.5% | Mar 24, 2023 | In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. Thi... |
| CVE-2022-20499 | MEDIUM | 5.5 | 0.2% | Mar 24, 2023 | In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to loca... |
| CVE-2022-20467 | MEDIUM | 5.5 | 0.1% | Mar 24, 2023 | In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a confused deputy. Th... |
| CVE-2022-47502 | HIGH | 7.8 | 1.0% | Mar 24, 2023 | Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes ar... |
| CVE-2022-38745 | HIGH | 7.8 | 0.9% | Mar 24, 2023 | Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead t... |
| CVE-2022-42948 | CRITICAL | 9.8 | 2.7% | Mar 24, 2023 | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted... |
| CVE-2022-28495 | CRITICAL | 9.8 | 2.4% | Mar 24, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebW... |
| CVE-2022-3146 | MEDIUM | 5.5 | 0.2% | Mar 23, 2023 | A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n... |
| CVE-2022-3101 | MEDIUM | 5.5 | 0.2% | Mar 23, 2023 | A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n... |
| CVE-2022-36413 | CRITICAL | 9.1 | 3.1% | Mar 23, 2023 | Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset o... |
| CVE-2022-47145 | MEDIUM | 6.1 | 0.5% | Mar 23, 2023 | Reflected Cross-Site Scripting (XSS) vulnerability in Blockonomics WordPress Bitcoin Payments – Blockonomics plugin <= 3... |
| CVE-2022-28496 | CRITICAL | 9.8 | 1.4% | Mar 23, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswor... |
| CVE-2022-47173 | MEDIUM | 4.8 | 0.4% | Mar 23, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nasirahmed Connect Contact Form 7, WooCommerce To Goog... |
| CVE-2022-28497 | CRITICAL | 9.8 | 1.4% | Mar 23, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_wri... |
| CVE-2022-47589 | MEDIUM | 4.8 | 0.4% | Mar 23, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in this.Functional CTT Expresso para WooCommerce plugin <... |
| CVE-2022-28493 | CRITICAL | 9.8 | 0.7% | Mar 23, 2023 | A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service, |
| CVE-2022-28491 | CRITICAL | 9.8 | 4.7% | Mar 23, 2023 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost functio... |
| CVE-2022-28492 | CRITICAL | 9.8 | 1.3% | Mar 23, 2023 | TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now