2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23542 | CRITICAL | 9.8 | 0.9% | Dec 20, 2022 | OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal s... |
| CVE-2022-23537 | CRITICAL | 9.8 | 1.0% | Dec 20, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2022-46020 | CRITICAL | 9.8 | 39.0% | Dec 20, 2022 | WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. |
| CVE-2022-46538 | CRITICAL | 9.8 | 2.4% | Dec 20, 2022 | Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteF... |
| CVE-2022-40624 | CRITICAL | 9.8 | 17.1% | Dec 20, 2022 | pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host ... |
| CVE-2022-46421 | CRITICAL | 9.8 | 3.2% | Dec 20, 2022 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Fou... |
| CVE-2022-25904 | CRITICAL | 9.8 | 0.9% | Dec 20, 2022 | All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify proper... |
| CVE-2022-25171 | CRITICAL | 9.8 | 2.4% | Dec 20, 2022 | The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitizatio... |
| CVE-2022-44109 | CRITICAL | 9.8 | 1.0% | Dec 19, 2022 | pdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*,... |
| CVE-2022-44108 | CRITICAL | 9.8 | 1.0% | Dec 19, 2022 | pdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc. |
| CVE-2022-44940 | CRITICAL | 9.1 | 1.0% | Dec 19, 2022 | Patchelf v0.9 was discovered to contain an out-of-bounds read via the function modifyRPath at src/patchelf.cc. |
| CVE-2022-40434 | CRITICAL | 9.8 | 1.3% | Dec 19, 2022 | Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page. |
| CVE-2022-38708 | CRITICAL | 9.1 | 0.4% | Dec 19, 2022 | IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attac... |
| CVE-2022-28173 | CRITICAL | 9.8 | 0.6% | Dec 19, 2022 | The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obta... |
| CVE-2022-4063 | CRITICAL | 9.8 | 9.5% | Dec 19, 2022 | The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, a... |
| CVE-2022-4050 | CRITICAL | 9.8 | 4.8% | Dec 19, 2022 | The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL s... |
| CVE-2022-4427 | CRITICAL | 9.8 | 0.7% | Dec 19, 2022 | Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via Tic... |
| CVE-2022-44456 | CRITICAL | 9.8 | 69.9% | Dec 19, 2022 | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS com... |
| CVE-2022-4607 | CRITICAL | 9.8 | 0.7% | Dec 18, 2022 | A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. Thi... |
| CVE-2022-4606 | CRITICAL | 9.8 | 35.4% | Dec 18, 2022 | PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3. |
| CVE-2022-4594 | CRITICAL | 9.8 | 0.6% | Dec 18, 2022 | A vulnerability was found in drogatkin TJWS2. It has been declared as critical. Affected by this vulnerability is the fu... |
| CVE-2022-4592 | CRITICAL | 9.8 | 0.5% | Dec 18, 2022 | A vulnerability was found in luckyshot CRMx and classified as critical. This issue affects the function get/save/delete/... |
| CVE-2022-37832 | CRITICAL | 9.8 | 0.6% | Dec 16, 2022 | Mutiny 7.2.0-10788 suffers from Hardcoded root password. |
| CVE-2022-4566 | CRITICAL | 9.8 | 0.8% | Dec 16, 2022 | A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unkn... |
| CVE-2022-42529 | CRITICAL | 9.8 | 0.4% | Dec 16, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now