2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41653 | CRITICAL | 9.8 | 0.7% | Dec 13, 2022 | Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user l... |
| CVE-2022-2757 | CRITICAL | 9.1 | 0.7% | Dec 13, 2022 | Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an ... |
| CVE-2022-46404 | CRITICAL | 9.8 | 1.8% | Dec 13, 2022 | A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Ma... |
| CVE-2022-45005 | CRITICAL | 9.8 | 5.4% | Dec 13, 2022 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output func... |
| CVE-2022-4454 | CRITICAL | 9.8 | 0.5% | Dec 13, 2022 | A vulnerability, which was classified as critical, has been found in m0ver bible-online. Affected by this issue is the f... |
| CVE-2022-46364 | CRITICAL | 9.8 | 1.9% | Dec 13, 2022 | A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.... |
| CVE-2022-27518 | CRITICAL | 9.8 | 6.9% | Dec 13, 2022 | Unauthenticated remote arbitrary code execution |
| CVE-2022-46353 | CRITICAL | 9.8 | 1.0% | Dec 13, 2022 | A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versi... |
| CVE-2022-43724 | CRITICAL | 9.8 | 0.6% | Dec 13, 2022 | A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database cre... |
| CVE-2022-20473 | CRITICAL | 9.8 | 8.9% | Dec 13, 2022 | In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This c... |
| CVE-2022-20472 | CRITICAL | 9.8 | 6.6% | Dec 13, 2022 | In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This c... |
| CVE-2022-4446 | CRITICAL | 9.8 | 1.3% | Dec 13, 2022 | PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. |
| CVE-2022-41271 | CRITICAL | 9.4 | 0.6% | Dec 13, 2022 | An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Pr... |
| CVE-2022-4314 | CRITICAL | 9.8 | 0.8% | Dec 12, 2022 | Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2. |
| CVE-2022-3982 | CRITICAL | 9.8 | 4.5% | Dec 12, 2022 | The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which c... |
| CVE-2022-3921 | CRITICAL | 9.8 | 21.2% | Dec 12, 2022 | The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthe... |
| CVE-2022-3915 | CRITICAL | 9.8 | 1.1% | Dec 12, 2022 | The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL state... |
| CVE-2022-3900 | CRITICAL | 9.8 | 19.0% | Dec 12, 2022 | The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before u... |
| CVE-2022-38656 | CRITICAL | 9.8 | 0.7% | Dec 12, 2022 | HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and ... |
| CVE-2022-37932 | CRITICAL | 9.8 | 2.6% | Dec 12, 2022 | A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S... |
| CVE-2022-37897 | CRITICAL | 9.8 | 1.7% | Dec 12, 2022 | There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially... |
| CVE-2022-3485 | CRITICAL | 9.8 | 0.9% | Dec 12, 2022 | In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password ... |
| CVE-2022-46682 | CRITICAL | 9.8 | 0.9% | Dec 12, 2022 | Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2022-4399 | CRITICAL | 9.8 | 0.7% | Dec 10, 2022 | A vulnerability was found in TicklishHoneyBee nodau. It has been rated as critical. Affected by this issue is some unkno... |
| CVE-2022-45145 | CRITICAL | 9.8 | 1.3% | Dec 10, 2022 | egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now