2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27628 | MEDIUM | 6.5 | 0.2% | Feb 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in AA-Team WZone – Lite Version plugin 3.1 Lite versions. |
| CVE-2022-25855 | HIGH | 7.8 | 1.0% | Feb 6, 2023 | All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to impr... |
| CVE-2022-25853 | HIGH | 7.8 | 1.1% | Feb 6, 2023 | All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to imp... |
| CVE-2022-45786 | HIGH | 8.1 | 0.9% | Feb 4, 2023 | There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for Po... |
| CVE-2022-24895 | HIGH | 8.8 | 0.8% | Feb 3, 2023 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating us... |
| CVE-2022-24894 | HIGH | 8.8 | 0.8% | Feb 3, 2023 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache... |
| CVE-2022-23498 | HIGH | 8.8 | 1.1% | Feb 3, 2023 | Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana c... |
| CVE-2022-48165 | HIGH | 7.5 | 3.3% | Feb 3, 2023 | An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthen... |
| CVE-2022-47762 | HIGH | 7.5 | 0.9% | Feb 3, 2023 | In gin-vue-admin < 2.5.5, the download module has a Path Traversal vulnerability. |
| CVE-2022-47070 | HIGH | 7.5 | 0.9% | Feb 3, 2023 | NVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the serve... |
| CVE-2022-45588 | HIGH | 7.8 | 0.2% | Feb 3, 2023 | All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) typ... |
| CVE-2022-45496 | HIGH | 7.8 | 0.6% | Feb 3, 2023 | Buffer overflow vulnerability in function json_parse_string in sheredom json.h before commit 0825301a07cbf51653882bf2b15... |
| CVE-2022-45493 | HIGH | 7.8 | 0.2% | Feb 3, 2023 | Buffer overflow vulnerability in function json_parse_key in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc... |
| CVE-2022-45492 | HIGH | 7.8 | 0.2% | Feb 3, 2023 | Buffer overflow vulnerability in function json_parse_number in sheredom json.h before commit 0825301a07cbf51653882bf2b15... |
| CVE-2022-45491 | HIGH | 7.8 | 0.3% | Feb 3, 2023 | Buffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153... |
| CVE-2022-42909 | MEDIUM | 5.4 | 0.4% | Feb 3, 2023 | WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and ass... |
| CVE-2022-42908 | MEDIUM | 5.4 | 0.4% | Feb 3, 2023 | WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to... |
| CVE-2022-31733 | CRITICAL | 9.1 | 0.4% | Feb 3, 2023 | Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are acc... |
| CVE-2022-34138 | HIGH | 7.5 | 0.6% | Feb 3, 2023 | Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers ... |
| CVE-2022-48074 | MEDIUM | 5.3 | 0.2% | Feb 3, 2023 | An issue in NoMachine before v8.2.3 allows attackers to execute arbitrary commands via a crafted .nxs file. |
| CVE-2022-4634 | HIGH | 7.8 | 5.3% | Feb 3, 2023 | All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vu... |
| CVE-2022-48023 | MEDIUM | 4.3 | 0.4% | Feb 3, 2023 | Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of ... |
| CVE-2022-48022 | MEDIUM | 4.3 | 0.5% | Feb 3, 2023 | An issue in the component /api/v1/mentions of Zammad v5.3.0 allows authenticated attackers with agent permissions to vie... |
| CVE-2022-48021 | CRITICAL | 9.8 | 0.9% | Feb 3, 2023 | A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message... |
| CVE-2022-47132 | HIGH | 8.8 | 0.9% | Feb 3, 2023 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now