2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-48317 | CRITICAL | 9.8 | 0.5% | Feb 20, 2023 | Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 a... |
| CVE-2022-47909 | HIGH | 7.8 | 0.4% | Feb 20, 2023 | Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <=... |
| CVE-2022-46836 | HIGH | 8.8 | 1.1% | Feb 20, 2023 | PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Check... |
| CVE-2022-46303 | HIGH | 7.5 | 1.1% | Feb 20, 2023 | Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allo... |
| CVE-2022-48329 | CRITICAL | 9.8 | 0.9% | Feb 20, 2023 | MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/Gala... |
| CVE-2022-48328 | CRITICAL | 9.8 | 1.3% | Feb 20, 2023 | app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_de... |
| CVE-2022-40348 | MEDIUM | 5.4 | 0.8% | Feb 18, 2023 | Cross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'em... |
| CVE-2022-48115 | MEDIUM | 6.1 | 0.4% | Feb 17, 2023 | The dropdown menu in jspreadsheet before v4.6.0 was discovered to be vulnerable to cross-site scripting (XSS). |
| CVE-2022-40021 | CRITICAL | 9.8 | 1.4% | Feb 17, 2023 | QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vuln... |
| CVE-2022-43579 | MEDIUM | 5.4 | 0.4% | Feb 17, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-... |
| CVE-2022-40231 | HIGH | 8.8 | 0.6% | Feb 17, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenti... |
| CVE-2022-34351 | HIGH | 7.5 | 0.4% | Feb 17, 2023 | IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain secu... |
| CVE-2022-43930 | HIGH | 7.5 | 0.5% | Feb 17, 2023 | IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive informa... |
| CVE-2022-41734 | HIGH | 7.5 | 0.5% | Feb 17, 2023 | IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a det... |
| CVE-2022-40232 | HIGH | 8.8 | 0.5% | Feb 17, 2023 | IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to ... |
| CVE-2022-20803 | HIGH | 7.5 | 1.1% | Feb 17, 2023 | A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unaut... |
| CVE-2022-43929 | HIGH | 7.5 | 0.7% | Feb 17, 2023 | IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially c... |
| CVE-2022-43927 | HIGH | 7.5 | 0.6% | Feb 17, 2023 | IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privile... |
| CVE-2022-36775 | MEDIUM | 6.5 | 0.4% | Feb 17, 2023 | IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, c... |
| CVE-2022-47986 | CRITICAL | 9.8 | 100.0% | Feb 17, 2023 | IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system,... |
| CVE-2022-45701 | HIGH | 8.8 | 45.3% | Feb 17, 2023 | Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature. |
| CVE-2022-40032 | CRITICAL | 9.8 | 20.7% | Feb 17, 2023 | SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' paramet... |
| CVE-2022-32972 | HIGH | 7.8 | 0.2% | Feb 17, 2023 | Infoblox BloxOne Endpoint for Windows through 2.2.7 allows DLL injection that can result in local privilege escalation. |
| CVE-2022-40347 | CRITICAL | 9.8 | 5.3% | Feb 17, 2023 | SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType... |
| CVE-2022-47703 | HIGH | 7.5 | 0.8% | Feb 16, 2023 | TIANJIE CPE906-3 is vulnerable to password disclosure. This is present on Software Version WEB5.0_LCD_20200513, Firmware... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now