2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2504 | CRITICAL | 9.8 | 0.6% | Feb 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Softw... |
| CVE-2022-48341 | HIGH | 8.8 | 1.0% | Feb 23, 2023 | ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Adminis... |
| CVE-2022-48149 | CRITICAL | 9.8 | 0.6% | Feb 22, 2023 | Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via ... |
| CVE-2022-45600 | HIGH | 8.8 | 2.3% | Feb 22, 2023 | Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers... |
| CVE-2022-45599 | CRITICAL | 9.8 | 1.0% | Feb 22, 2023 | Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, al... |
| CVE-2022-39983 | CRITICAL | 9.8 | 1.4% | Feb 22, 2023 | File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attack... |
| CVE-2022-29273 | MEDIUM | 6.1 | 59.6% | Feb 22, 2023 | pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters. |
| CVE-2022-43873 | HIGH | 8.8 | 0.6% | Feb 22, 2023 | An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute c... |
| CVE-2022-43870 | MEDIUM | 6.5 | 0.6% | Feb 22, 2023 | IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files... |
| CVE-2022-43578 | MEDIUM | 5.4 | 0.4% | Feb 22, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-... |
| CVE-2022-41567 | MEDIUM | 5.4 | 0.4% | Feb 22, 2023 | The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerabi... |
| CVE-2022-41566 | MEDIUM | 5.4 | 0.4% | Feb 22, 2023 | The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows... |
| CVE-2022-41565 | MEDIUM | 5.4 | 0.4% | Feb 22, 2023 | The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO ... |
| CVE-2022-41217 | CRITICAL | 9.8 | 0.7% | Feb 22, 2023 | Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malici... |
| CVE-2022-41216 | MEDIUM | 6.5 | 0.6% | Feb 22, 2023 | Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the syste... |
| CVE-2022-2883 | HIGH | 7.5 | 1.0% | Feb 22, 2023 | In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Serv... |
| CVE-2022-38779 | MEDIUM | 6.1 | 0.5% | Feb 22, 2023 | An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if th... |
| CVE-2022-46637 | CRITICAL | 9.8 | 1.5% | Feb 21, 2023 | Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services. |
| CVE-2022-48282 | HIGH | 7.2 | 1.0% | Feb 21, 2023 | Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitra... |
| CVE-2022-45677 | CRITICAL | 9.8 | 0.9% | Feb 21, 2023 | SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student... |
| CVE-2022-45564 | CRITICAL | 9.8 | 0.8% | Feb 21, 2023 | SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute... |
| CVE-2022-3353 | HIGH | 7.5 | 1.1% | Feb 21, 2023 | A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products. An attac... |
| CVE-2022-31394 | HIGH | 7.5 | 1.1% | Feb 21, 2023 | Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party ... |
| CVE-2022-4897 | MEDIUM | 6.1 | 0.9% | Feb 21, 2023 | The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back i... |
| CVE-2022-4791 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape o... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now