2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46095 | MEDIUM | 6.1 | 0.5% | Dec 21, 2022 | Sourcecodester Covid-19 Directory on Vaccination System 1.0 was discovered to contain a Cross-Site Scripting (XSS) vulne... |
| CVE-2022-36222 | HIGH | 8.4 | 0.3% | Dec 21, 2022 | Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5... |
| CVE-2022-36221 | MEDIUM | 6.5 | 0.8% | Dec 21, 2022 | Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to rea... |
| CVE-2022-4630 | MEDIUM | 5.3 | 0.6% | Dec 21, 2022 | Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master. |
| CVE-2022-40841 | MEDIUM | 6.1 | 0.5% | Dec 21, 2022 | A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrar... |
| CVE-2022-4287 | HIGH | 8.8 | 1.0% | Dec 21, 2022 | Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager 2022.3.26 and earlier on ... |
| CVE-2022-47581 | HIGH | 7.5 | 0.6% | Dec 21, 2022 | Isode M-Vault 16.0v0 through 17.x before 17.0v24 can crash upon an LDAP v1 bind request. |
| CVE-2022-44756 | MEDIUM | 6.5 | 0.4% | Dec 21, 2022 | Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information d... |
| CVE-2022-42454 | MEDIUM | 5.3 | 0.2% | Dec 21, 2022 | Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information dis... |
| CVE-2022-38655 | MEDIUM | 5.8 | 0.4% | Dec 21, 2022 | BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixl... |
| CVE-2022-40145 | CRITICAL | 9.8 | 2.4% | Dec 21, 2022 | This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the ... |
| CVE-2022-38065 | HIGH | 8.8 | 0.6% | Dec 21, 2022 | A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and pri... |
| CVE-2022-38060 | HIGH | 8.8 | 0.2% | Dec 21, 2022 | A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A miscon... |
| CVE-2022-46662 | MEDIUM | 6.7 | 0.4% | Dec 21, 2022 | Roxio Creator LJB starts another program with an unquoted file path. Since a registered Windows service path contains sp... |
| CVE-2022-46330 | HIGH | 7.8 | 0.4% | Dec 21, 2022 | Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop... |
| CVE-2022-46282 | HIGH | 7.8 | 0.2% | Dec 21, 2022 | Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a... |
| CVE-2022-44449 | MEDIUM | 4.8 | 0.7% | Dec 21, 2022 | Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacke... |
| CVE-2022-43543 | MEDIUM | 5.4 | 0.5% | Dec 21, 2022 | KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handlin... |
| CVE-2022-47635 | CRITICAL | 9.8 | 0.6% | Dec 21, 2022 | Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request ... |
| CVE-2022-25929 | MEDIUM | 5.4 | 0.8% | Dec 21, 2022 | The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user inp... |
| CVE-2022-25895 | HIGH | 7.5 | 1.3% | Dec 21, 2022 | All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sand... |
| CVE-2022-25893 | CRITICAL | 9.8 | 1.4% | Dec 21, 2022 | The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the We... |
| CVE-2022-24431 | CRITICAL | 9.8 | 1.3% | Dec 21, 2022 | All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper ... |
| CVE-2022-38546 | CRITICAL | 9.8 | 0.6% | Dec 21, 2022 | A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unaut... |
| CVE-2022-4617 | MEDIUM | 6.1 | 0.6% | Dec 21, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now