2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45598 | MEDIUM | 6.1 | 0.5% | Jan 31, 2023 | Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via im... |
| CVE-2022-28331 | CRITICAL | 9.8 | 1.6% | Jan 31, 2023 | On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sen... |
| CVE-2022-25147 | MEDIUM | 6.5 | 1.4% | Jan 31, 2023 | Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allow... |
| CVE-2022-24963 | CRITICAL | 9.8 | 1.5% | Jan 31, 2023 | Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker... |
| CVE-2022-46835 | HIGH | 7.5 | 0.9% | Jan 31, 2023 | IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, Identity... |
| CVE-2022-45435 | MEDIUM | 6.5 | 0.4% | Jan 31, 2023 | IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, Identity... |
| CVE-2022-44645 | HIGH | 8.8 | 1.9% | Jan 31, 2023 | In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code... |
| CVE-2022-44644 | MEDIUM | 6.5 | 1.2% | Jan 31, 2023 | In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could... |
| CVE-2022-39061 | MEDIUM | 6.5 | 0.7% | Jan 31, 2023 | ChangingTech MegaServiSignAdapter component has a vulnerability of Out-of-bounds Read due to insufficient validation for... |
| CVE-2022-39060 | CRITICAL | 9.8 | 0.9% | Jan 31, 2023 | ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote ... |
| CVE-2022-39059 | HIGH | 7.5 | 1.0% | Jan 31, 2023 | ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unau... |
| CVE-2022-45789 | CRITICAL | 9.8 | 1.4% | Jan 31, 2023 | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbu... |
| CVE-2022-25979 | MEDIUM | 6.1 | 0.6% | Jan 31, 2023 | Versions of the package jsuites before 5.0.1 are vulnerable to Cross-site Scripting (XSS) due to improper user-input san... |
| CVE-2022-25881 | HIGH | 7.5 | 1.6% | Jan 31, 2023 | This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request... |
| CVE-2022-21129 | CRITICAL | 9.8 | 2.8% | Jan 31, 2023 | Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization ... |
| CVE-2022-4898 | MEDIUM | 5.4 | 0.4% | Jan 31, 2023 | In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in t... |
| CVE-2022-4441 | HIGH | 8.8 | 0.6% | Jan 31, 2023 | Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u... |
| CVE-2022-4041 | HIGH | 8.8 | 0.6% | Jan 31, 2023 | Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u... |
| CVE-2022-44897 | MEDIUM | 6.1 | 0.8% | Jan 31, 2023 | A cross-site scripting (XSS) vulnerability in ApolloTheme AP PageBuilder component through 2.4.4 allows attackers to exe... |
| CVE-2022-40258 | MEDIUM | 5.3 | 0.4% | Jan 31, 2023 | AMI Megarac Weak password hashes for Redfish & API |
| CVE-2022-30421 | HIGH | 7.8 | 0.3% | Jan 31, 2023 | Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive info... |
| CVE-2022-48176 | HIGH | 7.8 | 0.4% | Jan 31, 2023 | Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94... |
| CVE-2022-45897 | MEDIUM | 6.5 | 0.4% | Jan 31, 2023 | On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtai... |
| CVE-2022-48175 | CRITICAL | 9.8 | 1.7% | Jan 30, 2023 | Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/i... |
| CVE-2022-32748 | HIGH | 8.3 | 0.1% | Jan 30, 2023 | A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now