2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24119 | CRITICAL | 9.8 | 0.7% | Dec 26, 2022 | Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device... |
| CVE-2022-24118 | CRITICAL | 9.1 | 0.6% | Dec 26, 2022 | Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory de... |
| CVE-2022-24117 | CRITICAL | 9.8 | 0.4% | Dec 26, 2022 | Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and i... |
| CVE-2022-24116 | CRITICAL | 9.8 | 0.3% | Dec 26, 2022 | Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II be... |
| CVE-2022-37310 | MEDIUM | 6.1 | 0.5% | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#... |
| CVE-2022-37309 | MEDIUM | 6.1 | 0.5% | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name. |
| CVE-2022-29853 | MEDIUM | 5.4 | 0.4% | Dec 26, 2022 | OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HT... |
| CVE-2022-29852 | MEDIUM | 5.4 | 0.4% | Dec 26, 2022 | OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked. |
| CVE-2022-37308 | MEDIUM | 6.1 | 0.5% | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages. |
| CVE-2022-37313 | MEDIUM | 5.3 | 0.7% | Dec 26, 2022 | OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA ... |
| CVE-2022-37312 | MEDIUM | 5.3 | 0.9% | Dec 26, 2022 | OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to ... |
| CVE-2022-37311 | MEDIUM | 5.3 | 0.9% | Dec 26, 2022 | OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect... |
| CVE-2022-37307 | MEDIUM | 6.1 | 0.5% | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG... |
| CVE-2022-31469 | MEDIUM | 6.1 | 0.5% | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ UR... |
| CVE-2022-4741 | MEDIUM | 6.5 | 0.8% | Dec 25, 2022 | A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function ConvertD... |
| CVE-2022-4740 | MEDIUM | 6.1 | 0.5% | Dec 25, 2022 | A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the functi... |
| CVE-2022-4739 | CRITICAL | 9.8 | 0.5% | Dec 25, 2022 | A vulnerability classified as critical was found in SourceCodester School Dormitory Management System 1.0. Affected by t... |
| CVE-2022-4738 | MEDIUM | 6.1 | 0.4% | Dec 25, 2022 | A vulnerability classified as problematic has been found in SourceCodester Blood Bank Management System 1.0. Affected is... |
| CVE-2022-4737 | CRITICAL | 9.8 | 0.6% | Dec 25, 2022 | A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue ... |
| CVE-2022-4736 | MEDIUM | 6.1 | 0.5% | Dec 25, 2022 | A vulnerability was found in Venganzas del Pasado and classified as problematic. Affected by this issue is some unknown ... |
| CVE-2022-41318 | HIGH | 8.6 | 2.8% | Dec 25, 2022 | A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection,... |
| CVE-2022-41317 | MEDIUM | 6.5 | 1.7% | Dec 25, 2022 | An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, ... |
| CVE-2022-40005 | HIGH | 8.8 | 34.8% | Dec 25, 2022 | Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the... |
| CVE-2022-37706 | HIGH | 7.8 | 5.5% | Dec 25, 2022 | enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th... |
| CVE-2022-4735 | MEDIUM | 6.1 | 0.5% | Dec 25, 2022 | A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function read... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now