2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36090 | HIGH | 8.1 | 0.9% | Sep 8, 2022 | XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14... |
| CVE-2022-20696 | HIGH | 8.8 | 0.3% | Sep 8, 2022 | A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated,... |
| CVE-2022-30079 | HIGH | 8.8 | 24.4% | Sep 8, 2022 | Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/a... |
| CVE-2022-38094 | HIGH | 8.8 | 1.5% | Sep 8, 2022 | OS command injection vulnerability in the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 al... |
| CVE-2022-36403 | HIGH | 7.8 | 0.2% | Sep 8, 2022 | Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker... |
| CVE-2022-35273 | HIGH | 8.8 | 1.5% | Sep 8, 2022 | OS command injection vulnerability in GUI setting page of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allow... |
| CVE-2022-34869 | HIGH | 8.8 | 0.9% | Sep 8, 2022 | Undocumented hidden command that can be executed from the telnet function of CentreCOM AR260S V2 firmware versions prior... |
| CVE-2022-28220 | HIGH | 7.5 | 1.7% | Sep 8, 2022 | Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS com... |
| CVE-2022-25897 | HIGH | 7.5 | 1.0% | Sep 8, 2022 | The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limita... |
| CVE-2022-37145 | HIGH | 7.5 | 0.9% | Sep 8, 2022 | The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configure... |
| CVE-2022-37144 | HIGH | 8.8 | 0.8% | Sep 8, 2022 | The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthent... |
| CVE-2022-38531 | HIGH | 8.8 | 1.8% | Sep 8, 2022 | FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function. |
| CVE-2022-37779 | HIGH | 7.2 | 1.7% | Sep 8, 2022 | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command exe... |
| CVE-2022-37778 | HIGH | 7.2 | 1.7% | Sep 8, 2022 | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command exe... |
| CVE-2022-37777 | HIGH | 7.2 | 1.7% | Sep 8, 2022 | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers 3.0.1.17 and earlier were discovered to contain a remote ... |
| CVE-2022-36081 | HIGH | 7.5 | 0.8% | Sep 7, 2022 | Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, Wikmd is vulnerable to path traversal when access... |
| CVE-2022-36079 | HIGH | 7.5 | 1.0% | Sep 7, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Internal fields ... |
| CVE-2022-36049 | HIGH | 7.5 | 1.0% | Sep 7, 2022 | Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a K... |
| CVE-2022-36073 | HIGH | 8.8 | 0.8% | Sep 7, 2022 | RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to c... |
| CVE-2022-36070 | HIGH | 7.3 | 0.3% | Sep 7, 2022 | Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes vario... |
| CVE-2022-36069 | HIGH | 7.3 | 1.5% | Sep 7, 2022 | Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a regis... |
| CVE-2022-30078 | HIGH | 8.8 | 1.9% | Sep 7, 2022 | NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0... |
| CVE-2022-1807 | HIGH | 7.2 | 1.0% | Sep 7, 2022 | Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall ol... |
| CVE-2022-37780 | HIGH | 7.2 | 1.7% | Sep 7, 2022 | Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command exe... |
| CVE-2022-36539 | HIGH | 7.5 | 1.2% | Sep 7, 2022 | WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now