2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-33323 | HIGH | 7.5 | 1.1% | Feb 2, 2023 | Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Seri... |
| CVE-2022-37034 | MEDIUM | 5.3 | 0.9% | Feb 1, 2023 | In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to d... |
| CVE-2022-47872 | HIGH | 8.8 | 0.9% | Feb 1, 2023 | A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbit... |
| CVE-2022-45783 | MEDIUM | 6.5 | 8.5% | Feb 1, 2023 | An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the do... |
| CVE-2022-45782 | HIGH | 8.8 | 0.6% | Feb 1, 2023 | An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure ... |
| CVE-2022-3913 | MEDIUM | 5.3 | 0.3% | Feb 1, 2023 | Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when ... |
| CVE-2022-37033 | MEDIUM | 6.5 | 0.8% | Feb 1, 2023 | In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to ... |
| CVE-2022-3083 | MEDIUM | 5.4 | 0.4% | Feb 1, 2023 | All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity... |
| CVE-2022-31364 | HIGH | 8.8 | 0.8% | Feb 1, 2023 | Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Over... |
| CVE-2022-31363 | HIGH | 8.8 | 0.8% | Feb 1, 2023 | Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Over... |
| CVE-2022-30904 | HIGH | 8.8 | 0.7% | Feb 1, 2023 | In Bestechnic Bluetooth Mesh SDK (BES2300) V1.0, a buffer overflow vulnerability can be triggered during provisioning, b... |
| CVE-2022-46934 | MEDIUM | 6.1 | 1.1% | Feb 1, 2023 | kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /control... |
| CVE-2022-47983 | MEDIUM | 5.4 | 0.4% | Feb 1, 2023 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2022-43922 | MEDIUM | 6.5 | 0.4% | Feb 1, 2023 | IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could disclose sensitive infor... |
| CVE-2022-4254 | HIGH | 8.8 | 0.9% | Feb 1, 2023 | sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters |
| CVE-2022-48094 | MEDIUM | 4.9 | 0.7% | Feb 1, 2023 | lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php. |
| CVE-2022-48093 | HIGH | 7.2 | 1.4% | Feb 1, 2023 | Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php... |
| CVE-2022-47717 | HIGH | 7.5 | 0.7% | Feb 1, 2023 | Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS). |
| CVE-2022-47715 | MEDIUM | 5.3 | 0.4% | Feb 1, 2023 | In Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic. |
| CVE-2022-47714 | CRITICAL | 9.8 | 0.6% | Feb 1, 2023 | Last Yard 22.09.8-1 does not enforce HSTS headers |
| CVE-2022-47003 | CRITICAL | 9.8 | 3.6% | Feb 1, 2023 | A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a... |
| CVE-2022-47002 | CRITICAL | 9.8 | 6.3% | Feb 1, 2023 | A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authenticatio... |
| CVE-2022-3990 | HIGH | 7.8 | 0.2% | Feb 1, 2023 | HPSFViewer might allow Escalation of Privilege. This potential vulnerability was remediated on July 29th, 2022. Customer... |
| CVE-2022-27538 | HIGH | 7 | 0.1% | Feb 1, 2023 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC produc... |
| CVE-2022-27537 | HIGH | 7.8 | 0.3% | Feb 1, 2023 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now