2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3792 | CRITICAL | 9.8 | 14.2% | Jan 10, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye ... |
| CVE-2022-43514 | CRITICAL | 9.8 | 1.5% | Jan 10, 2023 | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All ... |
| CVE-2022-47790 | CRITICAL | 9.8 | 0.8% | Jan 9, 2023 | Sourcecodester Dynamic Transaction Queuing System v1.0 is vulnerable to SQL Injection via /queuing/index.php?page=displa... |
| CVE-2022-43974 | CRITICAL | 9.8 | 1.7% | Jan 9, 2023 | MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a... |
| CVE-2022-33265 | CRITICAL | 9.8 | 0.4% | Jan 9, 2023 | Memory corruption due to information exposure in Powerline Communication Firmware while sending different MMEs from a si... |
| CVE-2022-25890 | CRITICAL | 9.8 | 1.3% | Jan 9, 2023 | All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input s... |
| CVE-2022-0668 | CRITICAL | 9.8 | 0.6% | Jan 8, 2023 | JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a... |
| CVE-2022-2666 | CRITICAL | 9.8 | 0.9% | Jan 7, 2023 | A vulnerability has been found in SourceCodester Loan Management System and classified as critical. This vulnerability a... |
| CVE-2022-1101 | CRITICAL | 9.8 | 1.0% | Jan 7, 2023 | A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issu... |
| CVE-2022-4880 | CRITICAL | 9.8 | 1.1% | Jan 7, 2023 | A vulnerability was found in stakira OpenUtau. It has been classified as critical. This affects the function VoicebankIn... |
| CVE-2022-39073 | CRITICAL | 9.8 | 3.3% | Jan 6, 2023 | There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an att... |
| CVE-2022-25923 | CRITICAL | 9.8 | 2.6% | Jan 6, 2023 | Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionali... |
| CVE-2022-44877 | CRITICAL | 9.8 | 100.0% | Jan 5, 2023 | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut... |
| CVE-2022-3929 | CRITICAL | 9.8 | 0.4% | Jan 5, 2023 | Communication between the client and the server application of the affected products is partially done using CORBA (Com... |
| CVE-2022-3927 | CRITICAL | 9.8 | 0.6% | Jan 5, 2023 | The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) fi... |
| CVE-2022-47544 | CRITICAL | 9.8 | 0.7% | Jan 5, 2023 | An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed. |
| CVE-2022-45995 | CRITICAL | 9.8 | 1.1% | Jan 5, 2023 | There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the... |
| CVE-2022-47523 | CRITICAL | 9.8 | 70.6% | Jan 5, 2023 | Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnera... |
| CVE-2022-22338 | CRITICAL | 9.8 | 0.7% | Jan 4, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection. A remote attacker c... |
| CVE-2022-45875 | CRITICAL | 9.8 | 2.5% | Jan 4, 2023 | Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulne... |
| CVE-2022-38627 | CRITICAL | 9.8 | 4.3% | Jan 3, 2023 | Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered ... |
| CVE-2022-32665 | CRITICAL | 9.8 | 1.5% | Jan 3, 2023 | In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of ... |
| CVE-2022-43931 | CRITICAL | 10 | 16.8% | Jan 3, 2023 | Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.... |
| CVE-2022-47618 | CRITICAL | 9.8 | 1.0% | Jan 3, 2023 | Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can ... |
| CVE-2022-39042 | CRITICAL | 9.8 | 1.5% | Jan 3, 2023 | aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerabil... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now