2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39041 | CRITICAL | 9.8 | 1.2% | Jan 3, 2023 | aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can ... |
| CVE-2022-39039 | CRITICAL | 9.8 | 1.0% | Jan 3, 2023 | aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this... |
| CVE-2022-4357 | CRITICAL | 9.8 | 1.0% | Jan 2, 2023 | The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2022-4298 | CRITICAL | 9.8 | 1.8% | Jan 2, 2023 | The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user ... |
| CVE-2022-4297 | CRITICAL | 9.8 | 3.6% | Jan 2, 2023 | The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a ... |
| CVE-2022-4099 | CRITICAL | 9.8 | 1.0% | Jan 2, 2023 | The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using th... |
| CVE-2022-4059 | CRITICAL | 9.8 | 4.8% | Jan 2, 2023 | The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it ... |
| CVE-2022-4049 | CRITICAL | 9.8 | 4.8% | Jan 2, 2023 | The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL stat... |
| CVE-2022-3241 | CRITICAL | 9.8 | 1.0% | Jan 2, 2023 | The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using t... |
| CVE-2022-42475 | CRITICAL | 9.8 | 99.5% | Jan 2, 2023 | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 ... |
| CVE-2022-34322 | CRITICAL | 9 | 0.8% | Jan 1, 2023 | Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScri... |
| CVE-2022-48198 | CRITICAL | 9.8 | 1.1% | Jan 1, 2023 | The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who contr... |
| CVE-2022-4866 | CRITICAL | 9 | 1.0% | Dec 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4865 | CRITICAL | 9 | 1.0% | Dec 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-48195 | CRITICAL | 9.8 | 0.9% | Dec 31, 2022 | An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the... |
| CVE-2022-47128 | CRITICAL | 9.8 | 1.0% | Dec 30, 2022 | Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey2 parameter at /goform/WifiBasicSet. |
| CVE-2022-47127 | CRITICAL | 9.8 | 0.9% | Dec 30, 2022 | Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd parameter at /goform/WifiBasicSet. |
| CVE-2022-47126 | CRITICAL | 9.8 | 0.9% | Dec 30, 2022 | Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet. |
| CVE-2022-47125 | CRITICAL | 9.8 | 0.9% | Dec 30, 2022 | Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn_5g parameter at /goform/WifiBasicSet. |
| CVE-2022-47124 | CRITICAL | 9.8 | 0.9% | Dec 30, 2022 | Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet. |
| CVE-2022-47123 | CRITICAL | 9.8 | 1.0% | Dec 30, 2022 | Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet. |
| CVE-2022-47122 | CRITICAL | 9.8 | 0.9% | Dec 30, 2022 | Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd_5g parameter at /goform/WifiBasicSet. |
| CVE-2022-47121 | CRITICAL | 9.8 | 0.9% | Dec 30, 2022 | Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet. |
| CVE-2022-47120 | CRITICAL | 9.8 | 0.9% | Dec 30, 2022 | Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet. |
| CVE-2022-47119 | CRITICAL | 9.8 | 0.9% | Dec 30, 2022 | Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the ssid parameter at /goform/WifiBasicSet. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now