2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34442 | CRITICAL | 9.8 | 0.4% | Jan 18, 2023 | Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabil... |
| CVE-2022-46733 | CRITICAL | 9.6 | 0.6% | Jan 18, 2023 | Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-s... |
| CVE-2022-45444 | CRITICAL | 9.8 | 0.9% | Jan 18, 2023 | Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded pass... |
| CVE-2022-41989 | CRITICAL | 9.8 | 0.8% | Jan 18, 2023 | Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not validate the le... |
| CVE-2022-46732 | CRITICAL | 9.8 | 0.8% | Jan 18, 2023 | Even if the authentication fails for local service authentication, the requested command could still execute regardless ... |
| CVE-2022-41903 | CRITICAL | 9.8 | 44.3% | Jan 17, 2023 | Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` sp... |
| CVE-2022-23521 | CRITICAL | 9.8 | 56.3% | Jan 17, 2023 | Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These ... |
| CVE-2022-46475 | CRITICAL | 9.8 | 9.5% | Jan 17, 2023 | D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main... |
| CVE-2022-43977 | CRITICAL | 9.8 | 0.6% | Jan 17, 2023 | An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessibl... |
| CVE-2022-43976 | CRITICAL | 9.8 | 0.7% | Jan 17, 2023 | An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct... |
| CVE-2022-36760 | CRITICAL | 9 | 1.9% | Jan 17, 2023 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Se... |
| CVE-2022-47853 | CRITICAL | 9.8 | 1.9% | Jan 17, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacke... |
| CVE-2022-23739 | CRITICAL | 9.8 | 1.2% | Jan 17, 2023 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileg... |
| CVE-2022-4447 | CRITICAL | 9.8 | 4.8% | Jan 16, 2023 | The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter before using it in a SQL sta... |
| CVE-2022-4101 | CRITICAL | 9.1 | 29.4% | Jan 16, 2023 | The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX a... |
| CVE-2022-4060 | CRITICAL | 9.8 | 42.7% | Jan 16, 2023 | The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, makin... |
| CVE-2022-4890 | CRITICAL | 9.8 | 0.8% | Jan 16, 2023 | A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some un... |
| CVE-2022-4889 | CRITICAL | 9.8 | 0.6% | Jan 15, 2023 | A vulnerability classified as critical was found in visegripped Stracker. Affected by this vulnerability is the function... |
| CVE-2022-1812 | CRITICAL | 9.8 | 30.8% | Jan 14, 2023 | Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10. |
| CVE-2022-45299 | CRITICAL | 9.8 | 1.3% | Jan 13, 2023 | An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi... |
| CVE-2022-46955 | CRITICAL | 9.8 | 0.6% | Jan 13, 2023 | Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ... |
| CVE-2022-46954 | CRITICAL | 9.8 | 0.6% | Jan 13, 2023 | Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ... |
| CVE-2022-3782 | CRITICAL | 9.1 | 5.8% | Jan 13, 2023 | keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs... |
| CVE-2022-21191 | CRITICAL | 9.8 | 1.5% | Jan 13, 2023 | Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input saniti... |
| CVE-2022-46502 | CRITICAL | 9.8 | 13.7% | Jan 13, 2023 | Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now