2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4873 | CRITICAL | 9.8 | 7.2% | Jan 11, 2023 | On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By p... |
| CVE-2022-4498 | CRITICAL | 9.8 | 1.8% | Jan 11, 2023 | In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication... |
| CVE-2022-46176 | MEDIUM | 5.9 | 0.6% | Jan 11, 2023 | Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key veri... |
| CVE-2022-41812 | — | — | — | Jan 11, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2022-41811 | — | — | — | Jan 11, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2022-41810 | — | — | — | Jan 11, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2022-41809 | — | — | — | Jan 11, 2023 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2022-4499 | HIGH | 7.5 | 0.7% | Jan 11, 2023 | TP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials i... |
| CVE-2022-4885 | MEDIUM | 5.9 | 0.7% | Jan 11, 2023 | A vulnerability has been found in sviehb jefferson up to 0.3 and classified as critical. This vulnerability affects unkn... |
| CVE-2022-4457 | MEDIUM | 5.5 | 0.2% | Jan 11, 2023 | Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijac... |
| CVE-2022-4428 | HIGH | 8 | 0.7% | Jan 11, 2023 | support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privil... |
| CVE-2022-40615 | CRITICAL | 9.8 | 0.7% | Jan 11, 2023 | IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could sen... |
| CVE-2022-34335 | MEDIUM | 6.5 | 0.7% | Jan 11, 2023 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server res... |
| CVE-2022-4543 | MEDIUM | 5.5 | 1.0% | Jan 11, 2023 | A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local atta... |
| CVE-2022-4415 | MEDIUM | 5.5 | 0.9% | Jan 11, 2023 | A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not ... |
| CVE-2022-47864 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php. |
| CVE-2022-47862 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php. |
| CVE-2022-47861 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php. |
| CVE-2022-47860 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php. |
| CVE-2022-47859 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php. |
| CVE-2022-47866 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php. |
| CVE-2022-47865 | CRITICAL | 9.8 | 0.9% | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php. |
| CVE-2022-4696 | HIGH | 7.8 | 0.4% | Jan 11, 2023 | There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If ... |
| CVE-2022-42967 | CRITICAL | 9.6 | 0.8% | Jan 11, 2023 | Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This dire... |
| CVE-2022-34441 | CRITICAL | 9.8 | 0.5% | Jan 11, 2023 | Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabil... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now