2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35977 | MEDIUM | 5.5 | 11.8% | Jan 20, 2023 | Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT... |
| CVE-2022-38112 | HIGH | 7.5 | 0.4% | Jan 20, 2023 | In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. |
| CVE-2022-38110 | MEDIUM | 5.4 | 0.4% | Jan 20, 2023 | In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated r... |
| CVE-2022-47747 | HIGH | 7.5 | 0.8% | Jan 20, 2023 | kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs. |
| CVE-2022-47732 | HIGH | 7.5 | 0.5% | Jan 20, 2023 | In Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and downl... |
| CVE-2022-43704 | MEDIUM | 5.9 | 1.9% | Jan 20, 2023 | The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requireme... |
| CVE-2022-27918 | — | — | — | Jan 20, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2022-27917 | — | — | — | Jan 20, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2022-27916 | — | — | — | Jan 20, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2022-27915 | — | — | — | Jan 20, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2022-25631 | HIGH | 7.8 | 0.2% | Jan 20, 2023 | Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnera... |
| CVE-2022-48126 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username para... |
| CVE-2022-48125 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password para... |
| CVE-2022-48124 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName para... |
| CVE-2022-48123 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername pa... |
| CVE-2022-48122 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid para... |
| CVE-2022-48121 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits param... |
| CVE-2022-43959 | MEDIUM | 4.9 | 1.0% | Jan 20, 2023 | Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remot... |
| CVE-2022-41441 | MEDIUM | 6.1 | 5.3% | Jan 20, 2023 | Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts o... |
| CVE-2022-40267 | CRITICAL | 9.1 | 1.2% | Jan 20, 2023 | Predictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F S... |
| CVE-2022-48191 | HIGH | 7 | 0.2% | Jan 20, 2023 | A vulnerability exists in Trend Micro Maximum Security 2022 (17.7) wherein a low-privileged user can write a known malic... |
| CVE-2022-20967 | MEDIUM | 5.4 | 0.5% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, re... |
| CVE-2022-20966 | MEDIUM | 5.4 | 27.6% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, re... |
| CVE-2022-20965 | MEDIUM | 5.4 | 0.6% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, re... |
| CVE-2022-20964 | HIGH | 8.8 | 30.6% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, re... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now