2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4855 | CRITICAL | 9.8 | 26.5% | Dec 30, 2022 | A vulnerability, which was classified as critical, was found in SourceCodester Lead Management System 1.0. Affected is a... |
| CVE-2022-48196 | CRITICAL | 9.8 | 0.9% | Dec 30, 2022 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.... |
| CVE-2022-36437 | CRITICAL | 9.1 | 1.0% | Dec 29, 2022 | The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate ... |
| CVE-2022-4779 | CRITICAL | 9.8 | 1.2% | Dec 29, 2022 | StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented ... |
| CVE-2022-4768 | CRITICAL | 9.8 | 0.7% | Dec 27, 2022 | A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key ... |
| CVE-2022-46442 | CRITICAL | 9.8 | 0.6% | Dec 27, 2022 | dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query. |
| CVE-2022-45963 | CRITICAL | 9.8 | 0.7% | Dec 27, 2022 | h3c firewall <= 3.10 ESS6703 has a privilege bypass vulnerability. |
| CVE-2022-45778 | CRITICAL | 9.8 | 0.7% | Dec 27, 2022 | https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There ... |
| CVE-2022-4726 | CRITICAL | 9.8 | 0.4% | Dec 27, 2022 | A vulnerability classified as critical was found in SourceCodester Sanitization Management System 1.0. Affected by this ... |
| CVE-2022-4725 | CRITICAL | 9.8 | 0.7% | Dec 27, 2022 | A vulnerability was found in AWS SDK 2.59.0. It has been rated as critical. This issue affects the function XpathUtils o... |
| CVE-2022-4724 | CRITICAL | 9.8 | 0.8% | Dec 27, 2022 | Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5. |
| CVE-2022-4719 | CRITICAL | 9.8 | 1.0% | Dec 27, 2022 | Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5. |
| CVE-2022-4748 | CRITICAL | 9.8 | 0.9% | Dec 27, 2022 | A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of t... |
| CVE-2022-46764 | CRITICAL | 9.8 | 2.1% | Dec 27, 2022 | A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated... |
| CVE-2022-4120 | CRITICAL | 9.8 | 18.1% | Dec 26, 2022 | The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user... |
| CVE-2022-4117 | CRITICAL | 9.8 | 5.0% | Dec 26, 2022 | The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX... |
| CVE-2022-4047 | CRITICAL | 9.8 | 6.2% | Dec 26, 2022 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be up... |
| CVE-2022-4742 | CRITICAL | 9.8 | 1.0% | Dec 26, 2022 | A vulnerability, which was classified as critical, has been found in json-pointer up to 0.6.1. Affected by this issue is... |
| CVE-2022-26969 | CRITICAL | 9.8 | 0.9% | Dec 26, 2022 | In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true. |
| CVE-2022-24119 | CRITICAL | 9.8 | 0.7% | Dec 26, 2022 | Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device... |
| CVE-2022-24118 | CRITICAL | 9.1 | 0.6% | Dec 26, 2022 | Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory de... |
| CVE-2022-24117 | CRITICAL | 9.8 | 0.4% | Dec 26, 2022 | Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and i... |
| CVE-2022-24116 | CRITICAL | 9.8 | 0.3% | Dec 26, 2022 | Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II be... |
| CVE-2022-4739 | CRITICAL | 9.8 | 0.5% | Dec 25, 2022 | A vulnerability classified as critical was found in SourceCodester School Dormitory Management System 1.0. Affected by t... |
| CVE-2022-4737 | CRITICAL | 9.8 | 0.6% | Dec 25, 2022 | A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now