2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3922 | MEDIUM | 4.8 | 0.5% | Dec 28, 2022 | The Broken Link Checker WordPress plugin before 1.11.20 does not sanitise and escape some of its settings, which could a... |
| CVE-2022-46179 | HIGH | 7.8 | 0.3% | Dec 28, 2022 | LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of... |
| CVE-2022-46174 | MEDIUM | 4.2 | 0.6% | Dec 28, 2022 | efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the... |
| CVE-2022-46173 | MEDIUM | 6.5 | 0.7% | Dec 28, 2022 | Elrond-GO is a go implementation for the Elrond Network protocol. Versions prior to 1.3.50 are subject to a processing i... |
| CVE-2022-46172 | MEDIUM | 6.4 | 0.5% | Dec 28, 2022 | authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, an... |
| CVE-2022-3347 | HIGH | 7.5 | 0.2% | Dec 28, 2022 | DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for inv... |
| CVE-2022-3346 | MEDIUM | 6.5 | 0.2% | Dec 28, 2022 | DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for inv... |
| CVE-2022-23555 | HIGH | 8.8 | 0.9% | Dec 28, 2022 | authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 20... |
| CVE-2022-4773 | LOW | 3.3 | 0.4% | Dec 28, 2022 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in cloudsync. Affected by this vulne... |
| CVE-2022-41967 | HIGH | 7.5 | 0.6% | Dec 28, 2022 | Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderF... |
| CVE-2022-41966 | HIGH | 7.5 | 8.7% | Dec 28, 2022 | XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate... |
| CVE-2022-23544 | MEDIUM | 6.1 | 1.6% | Dec 28, 2022 | MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testi... |
| CVE-2022-4772 | HIGH | 7.8 | 0.3% | Dec 27, 2022 | A vulnerability was found in Widoco and classified as critical. Affected by this issue is the function unZipIt of the fi... |
| CVE-2022-4768 | CRITICAL | 9.8 | 0.7% | Dec 27, 2022 | A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key ... |
| CVE-2022-46442 | CRITICAL | 9.8 | 0.6% | Dec 27, 2022 | dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query. |
| CVE-2022-45963 | CRITICAL | 9.8 | 0.7% | Dec 27, 2022 | h3c firewall <= 3.10 ESS6703 has a privilege bypass vulnerability. |
| CVE-2022-45778 | CRITICAL | 9.8 | 0.7% | Dec 27, 2022 | https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There ... |
| CVE-2022-3064 | HIGH | 7.5 | 1.7% | Dec 27, 2022 | Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory. |
| CVE-2022-2584 | HIGH | 7.5 | 0.7% | Dec 27, 2022 | The dag-pb codec can panic when decoding invalid blocks. |
| CVE-2022-2583 | LOW | 3.7 | 0.3% | Dec 27, 2022 | A race condition can cause incorrect HTTP request routing. |
| CVE-2022-2582 | MEDIUM | 4.3 | 0.5% | Dec 27, 2022 | The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash... |
| CVE-2022-3156 | HIGH | 7.8 | 0.4% | Dec 27, 2022 | A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. Users are grant... |
| CVE-2022-47968 | MEDIUM | 5.4 | 0.4% | Dec 27, 2022 | Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add applicat... |
| CVE-2022-45434 | MEDIUM | 5.9 | 0.7% | Dec 27, 2022 | Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. Af... |
| CVE-2022-45433 | LOW | 3.7 | 0.6% | Dec 27, 2022 | Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypas... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now