2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46478 | CRITICAL | 9.8 | 1.1% | Jan 13, 2023 | The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attacke... |
| CVE-2022-46471 | CRITICAL | 9.8 | 0.8% | Jan 13, 2023 | Online Health Care System v1.0 was discovered to contain a SQL injection vulnerability via the consulting_id parameter a... |
| CVE-2022-4616 | CRITICAL | 9.1 | 4.8% | Jan 13, 2023 | The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis ... |
| CVE-2022-39185 | CRITICAL | 9.8 | 0.6% | Jan 12, 2023 | EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user... |
| CVE-2022-39184 | CRITICAL | 9.8 | 0.8% | Jan 12, 2023 | EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication... |
| CVE-2022-3515 | CRITICAL | 9.8 | 1.6% | Jan 12, 2023 | A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can... |
| CVE-2022-4873 | CRITICAL | 9.8 | 7.2% | Jan 11, 2023 | On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By p... |
| CVE-2022-4498 | CRITICAL | 9.8 | 1.8% | Jan 11, 2023 | In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication... |
| CVE-2022-40615 | CRITICAL | 9.8 | 0.7% | Jan 11, 2023 | IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could sen... |
| CVE-2022-47864 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php. |
| CVE-2022-47862 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php. |
| CVE-2022-47861 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php. |
| CVE-2022-47860 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php. |
| CVE-2022-47859 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php. |
| CVE-2022-47866 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php. |
| CVE-2022-47865 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php. |
| CVE-2022-42967 | CRITICAL | 9.6 | 0.8% | Jan 11, 2023 | Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This dire... |
| CVE-2022-34441 | CRITICAL | 9.8 | 0.5% | Jan 11, 2023 | Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabil... |
| CVE-2022-34440 | CRITICAL | 9.8 | 0.5% | Jan 11, 2023 | Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabili... |
| CVE-2022-48253 | CRITICAL | 9.8 | 3.4% | Jan 11, 2023 | nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands... |
| CVE-2022-48252 | CRITICAL | 9.8 | 2.7% | Jan 11, 2023 | The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter)... |
| CVE-2022-43389 | CRITICAL | 9.8 | 0.6% | Jan 11, 2023 | A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, whic... |
| CVE-2022-4338 | CRITICAL | 9.8 | 1.3% | Jan 10, 2023 | An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch. |
| CVE-2022-4337 | CRITICAL | 9.8 | 1.3% | Jan 10, 2023 | An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch. |
| CVE-2022-4422 | CRITICAL | 9.8 | 0.6% | Jan 10, 2023 | Call Center System developed by Bulutses Information Technologies before version 3.0 has an unauthenticated Sql Injectio... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now