2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42471 | MEDIUM | 5.4 | 0.5% | Jan 3, 2023 | An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In Fort... |
| CVE-2022-41336 | MEDIUM | 4.8 | 0.6% | Jan 3, 2023 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 thro... |
| CVE-2022-39947 | HIGH | 8.8 | 2.9% | Jan 3, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC versio... |
| CVE-2022-35845 | HIGH | 8.8 | 1.1% | Jan 3, 2023 | Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE... |
| CVE-2022-38766 | HIGH | 8.1 | 0.7% | Jan 3, 2023 | The remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for e... |
| CVE-2022-4663 | MEDIUM | 6.1 | 0.7% | Jan 3, 2023 | The Members Import plugin for WordPress is vulnerable to Self Cross-Site Scripting via the user_login parameter in an im... |
| CVE-2022-4871 | HIGH | 7.2 | 0.7% | Jan 3, 2023 | A vulnerability classified as problematic was found in ummmmm nflpick-em.com up to 2.2.x. This vulnerability affects the... |
| CVE-2022-43931 | CRITICAL | 10 | 16.8% | Jan 3, 2023 | Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.... |
| CVE-2022-47908 | HIGH | 7.8 | 0.3% | Jan 3, 2023 | Stack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the inform... |
| CVE-2022-47618 | CRITICAL | 9.8 | 1.0% | Jan 3, 2023 | Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can ... |
| CVE-2022-47317 | HIGH | 7.8 | 0.2% | Jan 3, 2023 | Out-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information an... |
| CVE-2022-46360 | HIGH | 7.8 | 0.2% | Jan 3, 2023 | Out-of-bounds read vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker ... |
| CVE-2022-46309 | MEDIUM | 6.5 | 1.2% | Jan 3, 2023 | Vitals ESP upload function has a path traversal vulnerability. A remote attacker with general user privilege can exploit... |
| CVE-2022-46306 | HIGH | 7.8 | 0.9% | Jan 3, 2023 | ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters ... |
| CVE-2022-46305 | MEDIUM | 6.5 | 0.4% | Jan 3, 2023 | ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vul... |
| CVE-2022-46304 | HIGH | 8.8 | 1.5% | Jan 3, 2023 | ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. ... |
| CVE-2022-43448 | HIGH | 7.8 | 0.2% | Jan 3, 2023 | Out-of-bounds write vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker... |
| CVE-2022-43438 | HIGH | 8.8 | 0.8% | Jan 3, 2023 | The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as ... |
| CVE-2022-43437 | HIGH | 8.8 | 0.9% | Jan 3, 2023 | The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticate... |
| CVE-2022-43436 | HIGH | 8.8 | 0.9% | Jan 3, 2023 | The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker ... |
| CVE-2022-41645 | HIGH | 7.8 | 0.2% | Jan 3, 2023 | Out-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and... |
| CVE-2022-40740 | HIGH | 7.2 | 1.5% | Jan 3, 2023 | Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrat... |
| CVE-2022-39042 | CRITICAL | 9.8 | 1.5% | Jan 3, 2023 | aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerabil... |
| CVE-2022-39041 | CRITICAL | 9.8 | 1.2% | Jan 3, 2023 | aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can ... |
| CVE-2022-39040 | HIGH | 7.5 | 1.7% | Jan 3, 2023 | aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now