2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4861 | MEDIUM | 4.9 | 0.5% | Dec 30, 2022 | Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to... |
| CVE-2022-4860 | CRITICAL | 9.8 | 0.6% | Dec 30, 2022 | A vulnerability was found in KBase Metrics. It has been classified as critical. This affects the function upload_user_da... |
| CVE-2022-4859 | MEDIUM | 6.1 | 0.5% | Dec 30, 2022 | A vulnerability, which was classified as problematic, has been found in Joget up to 7.0.33. This issue affects the funct... |
| CVE-2022-4858 | HIGH | 7.5 | 0.5% | Dec 30, 2022 | Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive... |
| CVE-2022-44621 | CRITICAL | 9.8 | 3.0% | Dec 30, 2022 | Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. |
| CVE-2022-43396 | HIGH | 8.8 | 56.8% | Dec 30, 2022 | In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed.... |
| CVE-2022-4857 | HIGH | 7.8 | 0.7% | Dec 30, 2022 | A vulnerability was found in Modbus Tools Modbus Poll up to 9.10.0 and classified as critical. Affected by this issue is... |
| CVE-2022-4856 | HIGH | 7.8 | 0.6% | Dec 30, 2022 | A vulnerability has been found in Modbus Tools Modbus Slave up to 7.5.1 and classified as critical. Affected by this vul... |
| CVE-2022-4855 | CRITICAL | 9.8 | 26.5% | Dec 30, 2022 | A vulnerability, which was classified as critical, was found in SourceCodester Lead Management System 1.0. Affected is a... |
| CVE-2022-48196 | CRITICAL | 9.8 | 0.9% | Dec 30, 2022 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.... |
| CVE-2022-48194 | HIGH | 8.8 | 33.5% | Dec 30, 2022 | TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a De... |
| CVE-2022-44137 | HIGH | 7.2 | 0.8% | Dec 30, 2022 | SourceCodester Sanitization Management System 1.0 is vulnerable to SQL Injection. |
| CVE-2022-36437 | CRITICAL | 9.1 | 1.0% | Dec 29, 2022 | The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate ... |
| CVE-2022-30519 | MEDIUM | 6.1 | 2.5% | Dec 29, 2022 | XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary c... |
| CVE-2022-38212 | HIGH | 7.5 | 0.7% | Dec 29, 2022 | Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8... |
| CVE-2022-38211 | HIGH | 7.5 | 0.9% | Dec 29, 2022 | Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.9... |
| CVE-2022-38210 | MEDIUM | 6.1 | 0.5% | Dec 29, 2022 | There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below that may allow a r... |
| CVE-2022-38209 | MEDIUM | 6.1 | 0.5% | Dec 29, 2022 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, una... |
| CVE-2022-38208 | MEDIUM | 6.1 | 0.5% | Dec 29, 2022 | There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthent... |
| CVE-2022-38207 | MEDIUM | 6.1 | 0.5% | Dec 29, 2022 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote rem... |
| CVE-2022-38206 | MEDIUM | 6.1 | 0.5% | Dec 29, 2022 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote remo... |
| CVE-2022-38205 | HIGH | 7.5 | 1.5% | Dec 29, 2022 | In some non-default installations of Esri Portal for ArcGIS versions 10.9.1 and below, a directory traversal issue may a... |
| CVE-2022-38204 | MEDIUM | 6.1 | 0.5% | Dec 29, 2022 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, un... |
| CVE-2022-38203 | HIGH | 7.5 | 0.7% | Dec 29, 2022 | Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8... |
| CVE-2022-46181 | MEDIUM | 5.4 | 0.5% | Dec 29, 2022 | Gotify server is a simple server for sending and receiving messages in real-time per WebSocket. Versions prior to 2.2.2 ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now