2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-47377 | CRITICAL | 9.8 | 0.9% | Dec 16, 2022 | Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivilege... |
| CVE-2022-46393 | CRITICAL | 9.8 | 1.1% | Dec 15, 2022 | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow ... |
| CVE-2022-45969 | CRITICAL | 9.8 | 1.2% | Dec 15, 2022 | Alist v3.4.0 is vulnerable to Directory Traversal, |
| CVE-2022-40004 | CRITICAL | 9.6 | 0.9% | Dec 15, 2022 | Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted... |
| CVE-2022-46634 | CRITICAL | 9.8 | 2.1% | Dec 15, 2022 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled p... |
| CVE-2022-46631 | CRITICAL | 9.8 | 2.1% | Dec 15, 2022 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled p... |
| CVE-2022-44588 | CRITICAL | 9.8 | 2.3% | Dec 15, 2022 | Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress. |
| CVE-2022-44236 | CRITICAL | 9.8 | 0.8% | Dec 15, 2022 | Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability. |
| CVE-2022-42842 | CRITICAL | 9.8 | 2.2% | Dec 15, 2022 | The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ve... |
| CVE-2022-42837 | CRITICAL | 9.8 | 2.1% | Dec 15, 2022 | An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in... |
| CVE-2022-47408 | CRITICAL | 9.1 | 0.7% | Dec 14, 2022 | An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x b... |
| CVE-2022-47406 | CRITICAL | 9.8 | 0.4% | Dec 14, 2022 | An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x be... |
| CVE-2022-38488 | CRITICAL | 9.8 | 14.1% | Dec 14, 2022 | logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter. |
| CVE-2022-31702 | CRITICAL | 9.8 | 1.6% | Dec 14, 2022 | vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious act... |
| CVE-2022-46255 | CRITICAL | 9.8 | 1.4% | Dec 14, 2022 | An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server ... |
| CVE-2022-46072 | CRITICAL | 9.8 | 1.1% | Dec 14, 2022 | Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection. |
| CVE-2022-46071 | CRITICAL | 9.8 | 4.3% | Dec 14, 2022 | There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to by... |
| CVE-2022-46997 | CRITICAL | 9.8 | 1.1% | Dec 14, 2022 | Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the req... |
| CVE-2022-46996 | CRITICAL | 9.8 | 1.3% | Dec 14, 2022 | vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via ... |
| CVE-2022-46609 | CRITICAL | 9.8 | 1.4% | Dec 14, 2022 | Python3-RESTfulAPI commit d9907f14e9e25dcdb54f5b22252b0e9452e3970e and e772e0beee284c50946e94c54a1d43071ca78b74 was disc... |
| CVE-2022-44832 | CRITICAL | 9.8 | 3.9% | Dec 14, 2022 | D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTrigg... |
| CVE-2022-31358 | CRITICAL | 9 | 1.3% | Dec 14, 2022 | A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attack... |
| CVE-2022-4494 | CRITICAL | 9.8 | 0.5% | Dec 14, 2022 | A vulnerability, which was classified as critical, has been found in bspkrs MCPMappingViewer. Affected by this issue is ... |
| CVE-2022-4493 | CRITICAL | 9.8 | 0.5% | Dec 14, 2022 | A vulnerability classified as critical was found in scifio. Affected by this vulnerability is the function downloadAndUn... |
| CVE-2022-24377 | CRITICAL | 9.8 | 2.3% | Dec 14, 2022 | The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt funct... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now