2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44371 | CRITICAL | 9.8 | 1.3% | Dec 7, 2022 | hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE). |
| CVE-2022-42458 | CRITICAL | 9.8 | 1.1% | Dec 7, 2022 | Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a ... |
| CVE-2022-46742 | CRITICAL | 9.8 | 1.1% | Dec 7, 2022 | Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution. |
| CVE-2022-46741 | CRITICAL | 9.1 | 0.7% | Dec 7, 2022 | Out-of-bounds read in gather_tree in PaddlePaddle before 2.4. |
| CVE-2022-45026 | CRITICAL | 9.8 | 1.0% | Dec 7, 2022 | An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary comma... |
| CVE-2022-45025 | CRITICAL | 9.8 | 34.5% | Dec 7, 2022 | Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi... |
| CVE-2022-45010 | CRITICAL | 9.8 | 0.8% | Dec 7, 2022 | Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid paramete... |
| CVE-2022-41910 | CRITICAL | 9.1 | 0.4% | Dec 6, 2022 | TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that d... |
| CVE-2022-41902 | CRITICAL | 9.1 | 0.4% | Dec 6, 2022 | TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that d... |
| CVE-2022-45359 | CRITICAL | 9.8 | 13.5% | Dec 6, 2022 | Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress. |
| CVE-2022-46332 | CRITICAL | 9.6 | 0.6% | Dec 6, 2022 | The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vuln... |
| CVE-2022-44900 | CRITICAL | 9.1 | 2.2% | Dec 6, 2022 | A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea... |
| CVE-2022-46161 | CRITICAL | 9.8 | 1.6% | Dec 6, 2022 | pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfm... |
| CVE-2022-41559 | CRITICAL | 9.3 | 0.7% | Dec 6, 2022 | The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows ... |
| CVE-2022-35843 | CRITICAL | 9.8 | 0.9% | Dec 6, 2022 | An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.... |
| CVE-2022-46383 | CRITICAL | 9.8 | 0.7% | Dec 6, 2022 | RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 h... |
| CVE-2022-25912 | CRITICAL | 9.8 | 2.8% | Dec 6, 2022 | The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport proto... |
| CVE-2022-24439 | CRITICAL | 9.8 | 5.4% | Dec 6, 2022 | All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, w... |
| CVE-2022-40918 | CRITICAL | 9.8 | 1.8% | Dec 6, 2022 | Buffer overflow in firmware lewei_cam binary version 2.0.10 in Force 1 Discovery Wifi U818A HD+ FPV Drone allows attacke... |
| CVE-2022-38337 | CRITICAL | 9.1 | 0.7% | Dec 6, 2022 | When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this... |
| CVE-2022-43549 | CRITICAL | 9.8 | 0.7% | Dec 5, 2022 | Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechani... |
| CVE-2022-40259 | CRITICAL | 9.8 | 0.6% | Dec 5, 2022 | MegaRAC Default Credentials Vulnerability |
| CVE-2022-40242 | CRITICAL | 9.8 | 0.7% | Dec 5, 2022 | MegaRAC Default Credentials Vulnerability |
| CVE-2022-35255 | CRITICAL | 9.1 | 1.9% | Dec 5, 2022 | A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretK... |
| CVE-2022-32224 | CRITICAL | 9.8 | 2.4% | Dec 5, 2022 | A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now