2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45766 | CRITICAL | 9.1 | 0.8% | Feb 10, 2023 | Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Mana... |
| CVE-2022-46650 | MEDIUM | 4.9 | 12.3% | Feb 10, 2023 | Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACE... |
| CVE-2022-46649 | HIGH | 8.8 | 2.3% | Feb 10, 2023 | Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to e... |
| CVE-2022-4903 | HIGH | 8.1 | 0.6% | Feb 10, 2023 | A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function.... |
| CVE-2022-24410 | MEDIUM | 4.2 | 0.2% | Feb 10, 2023 | Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the... |
| CVE-2022-34454 | MEDIUM | 6.7 | 0.2% | Feb 10, 2023 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user cou... |
| CVE-2022-34452 | LOW | 2.7 | 0.4% | Feb 10, 2023 | PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerabil... |
| CVE-2022-43501 | CRITICAL | 9.1 | 0.6% | Feb 10, 2023 | KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insuffic... |
| CVE-2022-45699 | CRITICAL | 9.8 | 76.6% | Feb 10, 2023 | Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attack... |
| CVE-2022-3568 | HIGH | 8.8 | 0.6% | Feb 10, 2023 | The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' param... |
| CVE-2022-21940 | MEDIUM | 6.1 | 0.4% | Feb 9, 2023 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool... |
| CVE-2022-21939 | MEDIUM | 6.1 | 0.5% | Feb 9, 2023 | Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 pr... |
| CVE-2022-44572 | HIGH | 7.5 | 1.6% | Feb 9, 2023 | A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.... |
| CVE-2022-44571 | HIGH | 7.5 | 1.5% | Feb 9, 2023 | There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2... |
| CVE-2022-44570 | HIGH | 7.5 | 1.6% | Feb 9, 2023 | A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can ... |
| CVE-2022-44566 | HIGH | 7.5 | 1.3% | Feb 9, 2023 | A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outsi... |
| CVE-2022-43552 | MEDIUM | 5.9 | 2.5% | Feb 9, 2023 | A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports... |
| CVE-2022-43550 | CRITICAL | 9.8 | 1.8% | Feb 9, 2023 | A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching ... |
| CVE-2022-48302 | HIGH | 7.5 | 0.4% | Feb 9, 2023 | The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerabil... |
| CVE-2022-48301 | HIGH | 7.5 | 0.3% | Feb 9, 2023 | The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability m... |
| CVE-2022-48300 | HIGH | 7.5 | 0.4% | Feb 9, 2023 | The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect... |
| CVE-2022-48299 | HIGH | 7.5 | 0.4% | Feb 9, 2023 | The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect... |
| CVE-2022-48298 | HIGH | 7.5 | 0.4% | Feb 9, 2023 | The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability m... |
| CVE-2022-48297 | HIGH | 7.5 | 0.4% | Feb 9, 2023 | The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of... |
| CVE-2022-48296 | MEDIUM | 5.3 | 0.3% | Feb 9, 2023 | The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now