2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-47131 | MEDIUM | 4.8 | 0.4% | Feb 3, 2023 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page. |
| CVE-2022-47130 | MEDIUM | 4.3 | 0.6% | Feb 3, 2023 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an... |
| CVE-2022-38389 | CRITICAL | 9.1 | 1.3% | Feb 3, 2023 | IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when pro... |
| CVE-2022-22486 | CRITICAL | 9.1 | 1.4% | Feb 3, 2023 | IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when pro... |
| CVE-2022-48114 | CRITICAL | 9.8 | 0.9% | Feb 2, 2023 | RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable. |
| CVE-2022-48113 | CRITICAL | 9.8 | 0.9% | Feb 2, 2023 | A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet servic... |
| CVE-2022-48140 | MEDIUM | 5.4 | 0.4% | Feb 2, 2023 | DedeCMS v5.7.97 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /file_manage_view.... |
| CVE-2022-48130 | CRITICAL | 9.8 | 0.9% | Feb 2, 2023 | Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the para... |
| CVE-2022-48082 | CRITICAL | 9.8 | 0.6% | Feb 2, 2023 | Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.as... |
| CVE-2022-48079 | CRITICAL | 9.8 | 1.4% | Feb 2, 2023 | Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execu... |
| CVE-2022-46842 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions. |
| CVE-2022-46815 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin ... |
| CVE-2022-45807 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions. |
| CVE-2022-45067 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in DevsCred Exclusive Addons Elementor plugin <= 2.6.1 versions. |
| CVE-2022-44585 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions. |
| CVE-2022-40692 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions. |
| CVE-2022-3560 | MEDIUM | 5.5 | 0.2% | Feb 2, 2023 | A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service ... |
| CVE-2022-36401 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in TeraWallet – For WooCommerce plugin <= 1.3.24 versions. |
| CVE-2022-46604 | HIGH | 8.8 | 8.6% | Feb 2, 2023 | An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis... |
| CVE-2022-46552 | HIGH | 8.8 | 10.5% | Feb 2, 2023 | D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan... |
| CVE-2022-46965 | HIGH | 8.8 | 1.0% | Feb 2, 2023 | PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability. |
| CVE-2022-43665 | MEDIUM | 5.5 | 0.3% | Feb 2, 2023 | A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645. A specially-craft... |
| CVE-2022-2546 | MEDIUM | 4.7 | 1.2% | Feb 2, 2023 | The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the r... |
| CVE-2022-40269 | HIGH | 8.1 | 0.7% | Feb 2, 2023 | Authentication Bypass by Spoofing vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01... |
| CVE-2022-40268 | MEDIUM | 4.7 | 0.5% | Feb 2, 2023 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT2... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now