2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45148 | — | — | — | Jan 12, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-42273 | HIGH | 8.8 | 0.8% | Jan 12, 2023 | NVIDIA BMC contains a vulnerability in libwebsocket, where an authorized attacker can cause a buffer overflow and cause ... |
| CVE-2022-42272 | HIGH | 8.8 | 0.8% | Jan 12, 2023 | NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow, which may... |
| CVE-2022-25027 | HIGH | 7.5 | 1.0% | Jan 12, 2023 | The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authenticatio... |
| CVE-2022-25026 | HIGH | 7.5 | 24.2% | Jan 12, 2023 | A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensi... |
| CVE-2022-47102 | MEDIUM | 5.4 | 0.5% | Jan 12, 2023 | A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute a... |
| CVE-2022-46623 | HIGH | 7.8 | 0.4% | Jan 12, 2023 | Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter. |
| CVE-2022-46622 | MEDIUM | 6.1 | 0.5% | Jan 12, 2023 | A cross-site scripting (XSS) vulnerability in Judging Management System v1.0 allows attackers to execute arbitrary web s... |
| CVE-2022-45729 | MEDIUM | 6.1 | 0.5% | Jan 12, 2023 | A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute ar... |
| CVE-2022-45728 | MEDIUM | 6.1 | 0.5% | Jan 12, 2023 | Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2022-46472 | HIGH | 7.2 | 0.7% | Jan 12, 2023 | Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /hss/cla... |
| CVE-2022-4842 | MEDIUM | 5.5 | 0.2% | Jan 12, 2023 | A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user coul... |
| CVE-2022-4743 | HIGH | 7.5 | 1.3% | Jan 12, 2023 | A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerab... |
| CVE-2022-3977 | HIGH | 7.8 | 0.3% | Jan 12, 2023 | A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This i... |
| CVE-2022-3628 | MEDIUM | 6.6 | 0.5% | Jan 12, 2023 | A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user conne... |
| CVE-2022-3145 | MEDIUM | 4.7 | 0.4% | Jan 12, 2023 | An open redirect vulnerability exists in Okta OIDC Middleware prior to version 5.0.0 allowing an attacker to redirect a ... |
| CVE-2022-43591 | HIGH | 8.8 | 1.1% | Jan 12, 2023 | A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javas... |
| CVE-2022-40983 | HIGH | 8.8 | 1.1% | Jan 12, 2023 | An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted jav... |
| CVE-2022-46372 | HIGH | 8.8 | 0.9% | Jan 12, 2023 | Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow ... |
| CVE-2022-46371 | MEDIUM | 5.3 | 0.4% | Jan 12, 2023 | Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default admi... |
| CVE-2022-46370 | HIGH | 7.5 | 0.2% | Jan 12, 2023 | Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification... |
| CVE-2022-46369 | MEDIUM | 5.4 | 0.4% | Jan 12, 2023 | Rumpus - FTP server version 9.0.7.1 Persistent cross-site scripting (PXSS) – vulnerability may allow inserting scripts i... |
| CVE-2022-46368 | HIGH | 8.8 | 0.3% | Jan 12, 2023 | Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on b... |
| CVE-2022-46367 | HIGH | 8.8 | 0.3% | Jan 12, 2023 | Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege esca... |
| CVE-2022-39187 | MEDIUM | 6.1 | 0.4% | Jan 12, 2023 | Rumpus - FTP server version 9.0.7.1 has a Reflected cross-site scripting (RXSS) vulnerability through unspecified vector... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now