2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38088 | MEDIUM | 6.5 | 2.3% | Jan 26, 2023 | A directory traversal vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-21072... |
| CVE-2022-38066 | HIGH | 8.8 | 7.1% | Jan 26, 2023 | An OS command injection vulnerability exists in the httpd SNMP functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-1410... |
| CVE-2022-36279 | HIGH | 8.8 | 3.2% | Jan 26, 2023 | A stack-based buffer overflow vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.... |
| CVE-2022-4510 | HIGH | 7.8 | 21.8% | Jan 26, 2023 | A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By craf... |
| CVE-2022-4092 | HIGH | 8 | 1.4% | Jan 26, 2023 | An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to cr... |
| CVE-2022-4054 | MEDIUM | 5.5 | 0.7% | Jan 26, 2023 | An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting fro... |
| CVE-2022-48199 | HIGH | 8.8 | 0.7% | Jan 26, 2023 | SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges... |
| CVE-2022-47767 | CRITICAL | 9.8 | 1.2% | Jan 26, 2023 | A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to t... |
| CVE-2022-47615 | CRITICAL | 9.8 | 5.1% | Jan 26, 2023 | Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. |
| CVE-2022-47100 | HIGH | 7.5 | 1.0% | Jan 26, 2023 | A vulnerability in Sengled Smart bulb 0x0000024 allows attackers to arbitrarily perform a factory reset on the device vi... |
| CVE-2022-47073 | MEDIUM | 5.4 | 0.6% | Jan 26, 2023 | A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbit... |
| CVE-2022-47052 | MEDIUM | 6.1 | 0.6% | Jan 26, 2023 | The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can b... |
| CVE-2022-47042 | HIGH | 8.8 | 1.0% | Jan 26, 2023 | MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/wri... |
| CVE-2022-47040 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running ... |
| CVE-2022-46999 | CRITICAL | 9.8 | 1.0% | Jan 26, 2023 | Tuzicms v2.0.6 was discovered to contain a SQL injection vulnerability via the component \App\Manage\Controller\UserCont... |
| CVE-2022-46998 | CRITICAL | 9.8 | 1.1% | Jan 26, 2023 | An issue in the website background of taocms v3.0.2 allows attackers to execute a Server-Side Request Forgery (SSRF). |
| CVE-2022-46957 | MEDIUM | 6.1 | 0.5% | Jan 26, 2023 | Sourcecodester.com Online Graduate Tracer System V 1.0.0 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-46624 | MEDIUM | 6.1 | 0.5% | Jan 26, 2023 | A cross-site scripting (XSS) vulnerability in Online Graduate Tracer System v1.0.0 allows attackers to execute arbitrary... |
| CVE-2022-46128 | MEDIUM | 6.1 | 0.5% | Jan 26, 2023 | phpgurukul Doctor Appointment Management System V 1.0.0 is vulnerable to Cross Site Scripting (XSS) via searchdata=. |
| CVE-2022-45920 | HIGH | 7.5 | 0.9% | Jan 26, 2023 | In Softing uaToolkit Embedded before 1.41, a malformed CreateMonitoredItems request may cause a memory leak. |
| CVE-2022-45820 | HIGH | 8.8 | 1.0% | Jan 26, 2023 | SQL Injection (SQLi) vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. |
| CVE-2022-45808 | CRITICAL | 9.8 | 4.3% | Jan 26, 2023 | SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. |
| CVE-2022-45730 | MEDIUM | 6.1 | 0.5% | Jan 26, 2023 | A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute ar... |
| CVE-2022-44297 | CRITICAL | 9.8 | 1.0% | Jan 26, 2023 | SiteServer CMS 7.1.3 has a SQL injection vulnerability the background. |
| CVE-2022-44018 | HIGH | 7.5 | 0.8% | Jan 26, 2023 | In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now