2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45913 | MEDIUM | 6.1 | 0.4% | Jan 6, 2023 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via one of attributes in webmail URLs to execut... |
| CVE-2022-45911 | MEDIUM | 6.1 | 0.4% | Jan 6, 2023 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbit... |
| CVE-2022-44939 | HIGH | 7.8 | 0.4% | Jan 6, 2023 | Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the component Text... |
| CVE-2022-41613 | HIGH | 7.8 | 0.2% | Jan 6, 2023 | Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when ... |
| CVE-2022-40201 | HIGH | 7.8 | 0.3% | Jan 6, 2023 | Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to a Stack-Based Buffer Overflow wh... |
| CVE-2022-2484 | HIGH | 7.8 | 0.2% | Jan 6, 2023 | The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker... |
| CVE-2022-2483 | HIGH | 7.1 | 0.2% | Jan 6, 2023 | The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for fi... |
| CVE-2022-2482 | HIGH | 8.8 | 0.2% | Jan 6, 2023 | A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow a... |
| CVE-2022-47976 | HIGH | 7.5 | 0.4% | Jan 6, 2023 | The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful ... |
| CVE-2022-47975 | HIGH | 7.5 | 0.6% | Jan 6, 2023 | The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availa... |
| CVE-2022-47974 | MEDIUM | 6.5 | 0.2% | Jan 6, 2023 | The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerabilit... |
| CVE-2022-46762 | HIGH | 7.5 | 0.4% | Jan 6, 2023 | The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect d... |
| CVE-2022-46761 | HIGH | 7.5 | 0.3% | Jan 6, 2023 | The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this ... |
| CVE-2022-39073 | CRITICAL | 9.8 | 3.3% | Jan 6, 2023 | There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an att... |
| CVE-2022-39072 | MEDIUM | 5.4 | 0.3% | Jan 6, 2023 | There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input... |
| CVE-2022-44149 | HIGH | 8.8 | 64.4% | Jan 6, 2023 | The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by... |
| CVE-2022-4879 | HIGH | 7.5 | 0.5% | Jan 6, 2023 | A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vuln... |
| CVE-2022-4878 | MEDIUM | 5.3 | 0.7% | Jan 6, 2023 | A vulnerability classified as critical has been found in JATOS. Affected is the function ZipUtil of the file modules/com... |
| CVE-2022-45935 | MEDIUM | 5.5 | 0.4% | Jan 6, 2023 | Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to ac... |
| CVE-2022-45787 | MEDIUM | 5.5 | 0.3% | Jan 6, 2023 | Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclo... |
| CVE-2022-25923 | CRITICAL | 9.8 | 2.6% | Jan 6, 2023 | Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionali... |
| CVE-2022-42979 | HIGH | 8.8 | 24.3% | Jan 6, 2023 | Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows ... |
| CVE-2022-44870 | MEDIUM | 6.1 | 0.5% | Jan 6, 2023 | A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary w... |
| CVE-2022-40049 | HIGH | 7.5 | 1.0% | Jan 6, 2023 | SQL injection vulnerability in sourcecodester Theme Park Ticketing System 1.0 allows remote attackers to view sensitive ... |
| CVE-2022-44541 | — | — | — | Jan 6, 2023 | Rejected reason: CVE was unused by HPE. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now