2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-48295 | HIGH | 7.5 | 0.3% | Feb 9, 2023 | The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to ... |
| CVE-2022-48294 | HIGH | 7.5 | 0.4% | Feb 9, 2023 | The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may af... |
| CVE-2022-48293 | MEDIUM | 6.5 | 0.2% | Feb 9, 2023 | The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentia... |
| CVE-2022-48292 | MEDIUM | 6.5 | 0.2% | Feb 9, 2023 | The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect ... |
| CVE-2022-48290 | CRITICAL | 9.1 | 0.4% | Feb 9, 2023 | The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may af... |
| CVE-2022-48289 | HIGH | 7.5 | 0.4% | Feb 9, 2023 | The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this v... |
| CVE-2022-48288 | HIGH | 7.5 | 0.4% | Feb 9, 2023 | The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this v... |
| CVE-2022-48287 | HIGH | 7.5 | 0.4% | Feb 9, 2023 | The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data in... |
| CVE-2022-48286 | HIGH | 7.5 | 0.4% | Feb 9, 2023 | The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerab... |
| CVE-2022-30564 | MEDIUM | 5.3 | 0.4% | Feb 9, 2023 | Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a spe... |
| CVE-2022-43440 | HIGH | 7.8 | 0.2% | Feb 9, 2023 | Uncontrolled Search Path Element in Checkmk Agent in Tribe29 Checkmk before 2.1.0p1, before 2.0.0p25 and before 1.6.0p29... |
| CVE-2022-47648 | HIGH | 8.8 | 0.4% | Feb 8, 2023 | An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring an... |
| CVE-2022-45982 | CRITICAL | 9.8 | 1.2% | Feb 8, 2023 | thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to e... |
| CVE-2022-38778 | MEDIUM | 6.5 | 0.9% | Feb 8, 2023 | A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated us... |
| CVE-2022-38777 | HIGH | 7.8 | 0.3% | Feb 8, 2023 | An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged... |
| CVE-2022-4450 | HIGH | 7.5 | 20.4% | Feb 8, 2023 | The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any h... |
| CVE-2022-4304 | MEDIUM | 5.9 | 16.2% | Feb 8, 2023 | A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a p... |
| CVE-2022-34350 | HIGH | 7.5 | 0.6% | Feb 8, 2023 | IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerable t... |
| CVE-2022-45755 | MEDIUM | 5.4 | 0.4% | Feb 8, 2023 | Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page ... |
| CVE-2022-45527 | CRITICAL | 9.8 | 0.9% | Feb 8, 2023 | File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to d... |
| CVE-2022-45526 | CRITICAL | 9.8 | 1.0% | Feb 8, 2023 | SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbi... |
| CVE-2022-42438 | HIGH | 8.8 | 0.5% | Feb 8, 2023 | IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin function... |
| CVE-2022-35720 | MEDIUM | 5.5 | 0.1% | Feb 8, 2023 | IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptogr... |
| CVE-2022-34362 | MEDIUM | 4.6 | 0.4% | Feb 8, 2023 | IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the H... |
| CVE-2022-41620 | HIGH | 8.8 | 0.3% | Feb 8, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now