2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46530 | HIGH | 7.5 | 0.8% | Dec 20, 2022 | Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mac parameter at /goform/GetParentControlInfo. |
| CVE-2022-45666 | HIGH | 7.5 | 0.8% | Dec 20, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset functi... |
| CVE-2022-45665 | HIGH | 7.5 | 0.8% | Dec 20, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm funct... |
| CVE-2022-44643 | HIGH | 8.8 | 0.5% | Dec 20, 2022 | A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more acc... |
| CVE-2022-40624 | CRITICAL | 9.8 | 17.1% | Dec 20, 2022 | pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host ... |
| CVE-2022-45942 | HIGH | 8.8 | 22.0% | Dec 20, 2022 | A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4. |
| CVE-2022-46421 | CRITICAL | 9.8 | 3.2% | Dec 20, 2022 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Fou... |
| CVE-2022-25940 | HIGH | 7.5 | 1.2% | Dec 20, 2022 | All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and... |
| CVE-2022-25931 | HIGH | 7.5 | 1.3% | Dec 20, 2022 | All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and s... |
| CVE-2022-25904 | CRITICAL | 9.8 | 0.9% | Dec 20, 2022 | All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify proper... |
| CVE-2022-25171 | CRITICAL | 9.8 | 2.4% | Dec 20, 2022 | The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitizatio... |
| CVE-2022-47578 | HIGH | 7.8 | 1.0% | Dec 20, 2022 | An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite ... |
| CVE-2022-47577 | HIGH | 7.8 | 1.1% | Dec 20, 2022 | An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite ... |
| CVE-2022-47551 | MEDIUM | 6.5 | 0.6% | Dec 20, 2022 | Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The ro... |
| CVE-2022-46403 | HIGH | 8.6 | 0.8% | Dec 19, 2022 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject... |
| CVE-2022-46402 | MEDIUM | 6.5 | 0.5% | Dec 19, 2022 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_r... |
| CVE-2022-46401 | MEDIUM | 5.4 | 0.7% | Dec 19, 2022 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncR... |
| CVE-2022-46400 | MEDIUM | 5.4 | 0.6% | Dec 19, 2022 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers ... |
| CVE-2022-46399 | HIGH | 7.5 | 0.7% | Dec 19, 2022 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive w... |
| CVE-2022-44109 | CRITICAL | 9.8 | 1.0% | Dec 19, 2022 | pdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*,... |
| CVE-2022-44108 | CRITICAL | 9.8 | 1.0% | Dec 19, 2022 | pdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc. |
| CVE-2022-3752 | HIGH | 7.5 | 1.2% | Dec 19, 2022 | An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loadin... |
| CVE-2022-44940 | CRITICAL | 9.1 | 1.0% | Dec 19, 2022 | Patchelf v0.9 was discovered to contain an out-of-bounds read via the function modifyRPath at src/patchelf.cc. |
| CVE-2022-40434 | CRITICAL | 9.8 | 1.3% | Dec 19, 2022 | Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page. |
| CVE-2022-23543 | MEDIUM | 5.4 | 0.3% | Dec 19, 2022 | Silverware Games is a social network where people can play games online. Users can attach URLs to YouTube videos, the si... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now