2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43765 | HIGH | 7.5 | 0.6% | Feb 8, 2023 | B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which ... |
| CVE-2022-43764 | CRITICAL | 9.8 | 0.8% | Feb 8, 2023 | Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07... |
| CVE-2022-43763 | HIGH | 7.5 | 0.6% | Feb 8, 2023 | Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server... |
| CVE-2022-43762 | CRITICAL | 9.8 | 0.6% | Feb 8, 2023 | Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages |
| CVE-2022-43761 | HIGH | 7.5 | 0.6% | Feb 8, 2023 | Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and ch... |
| CVE-2022-2094 | MEDIUM | 6.1 | 0.5% | Feb 8, 2023 | The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back ... |
| CVE-2022-45192 | MEDIUM | 6.5 | 0.2% | Feb 8, 2023 | An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of servi... |
| CVE-2022-45191 | MEDIUM | 6.5 | 0.2% | Feb 8, 2023 | An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of servi... |
| CVE-2022-45190 | MEDIUM | 5.3 | 0.3% | Feb 8, 2023 | An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in... |
| CVE-2022-40480 | MEDIUM | 6.5 | 0.3% | Feb 8, 2023 | Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers... |
| CVE-2022-47418 | MEDIUM | 5.4 | 0.5% | Feb 7, 2023 | LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script... |
| CVE-2022-47419 | MEDIUM | 5.4 | 0.5% | Feb 7, 2023 | An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the in-product ta... |
| CVE-2022-47417 | MEDIUM | 5.4 | 0.5% | Feb 7, 2023 | LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script... |
| CVE-2022-47416 | MEDIUM | 5.4 | 0.5% | Feb 7, 2023 | LogicalDOC Enterprise is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the i... |
| CVE-2022-47415 | MEDIUM | 5.4 | 0.5% | Feb 7, 2023 | LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script... |
| CVE-2022-47414 | MEDIUM | 5.4 | 0.5% | Feb 7, 2023 | If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in ... |
| CVE-2022-47413 | MEDIUM | 5.4 | 0.5% | Feb 7, 2023 | Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II")... |
| CVE-2022-46663 | HIGH | 7.5 | 1.4% | Feb 7, 2023 | In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal. |
| CVE-2022-45768 | HIGH | 8.8 | 28.7% | Feb 7, 2023 | Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker ... |
| CVE-2022-47412 | MEDIUM | 5.4 | 0.6% | Feb 7, 2023 | Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, ... |
| CVE-2022-4883 | HIGH | 8.8 | 1.2% | Feb 7, 2023 | A flaw was found in libXpm. When processing files with .Z or .gz extensions, the library calls external programs to comp... |
| CVE-2022-46285 | HIGH | 7.5 | 1.3% | Feb 7, 2023 | A flaw was found in libXpm. This issue occurs when parsing a file with a comment not closed; the end-of-file condition w... |
| CVE-2022-24990 | HIGH | 7.5 | 84.0% | Feb 7, 2023 | TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen... |
| CVE-2022-41313 | MEDIUM | 5.4 | 1.1% | Feb 7, 2023 | A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industri... |
| CVE-2022-41312 | MEDIUM | 5.4 | 1.1% | Feb 7, 2023 | A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industri... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now