2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45145 | CRITICAL | 9.8 | 1.3% | Dec 10, 2022 | egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape... |
| CVE-2022-4396 | MEDIUM | 5.4 | 0.6% | Dec 10, 2022 | A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option o... |
| CVE-2022-23485 | LOW | 3.7 | 0.4% | Dec 10, 2022 | Sentry is an error tracking and performance monitoring platform. In versions of the sentry python library prior to 22.11... |
| CVE-2022-23510 | HIGH | 8.8 | 0.9% | Dec 9, 2022 | cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL... |
| CVE-2022-23497 | HIGH | 7.5 | 0.8% | Dec 9, 2022 | FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition... |
| CVE-2022-45292 | MEDIUM | 5.3 | 0.5% | Dec 9, 2022 | User invites for Funkwhale v1.2.8 do not permanently expire after being used for signup and can be used again after an a... |
| CVE-2022-34297 | MEDIUM | 5.4 | 0.6% | Dec 9, 2022 | Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field. |
| CVE-2022-46166 | CRITICAL | 9.8 | 1.4% | Dec 9, 2022 | Spring boot admins is an open source administrative user interface for management of spring boot applications. All users... |
| CVE-2022-46157 | HIGH | 8.8 | 1.4% | Dec 9, 2022 | Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119... |
| CVE-2022-44790 | HIGH | 7.5 | 0.6% | Dec 9, 2022 | Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could s... |
| CVE-2022-4390 | CRITICAL | 10 | 0.9% | Dec 9, 2022 | A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 ... |
| CVE-2022-2993 | CRITICAL | 9.8 | 0.6% | Dec 9, 2022 | There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current key... |
| CVE-2022-45290 | CRITICAL | 9.1 | 0.9% | Dec 9, 2022 | Kbase Doc v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /web/IndexController... |
| CVE-2022-41299 | MEDIUM | 5.4 | 0.3% | Dec 9, 2022 | IBM Cloud Transformation Advisor 2.0.1 through 3.3.1 is vulnerable to cross-site scripting. This vulnerability allows us... |
| CVE-2022-4336 | MEDIUM | 5.4 | 0.3% | Dec 9, 2022 | In BAOTA linux panel there exists a stored xss vulnerability attackers can use to obtain sensitive information via the l... |
| CVE-2022-4170 | CRITICAL | 9.8 | 2.1% | Dec 9, 2022 | The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker ca... |
| CVE-2022-3724 | HIGH | 7.5 | 2.3% | Dec 9, 2022 | Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or cra... |
| CVE-2022-3259 | HIGH | 7.4 | 0.5% | Dec 9, 2022 | Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks. |
| CVE-2022-29839 | MEDIUM | 5.5 | 0.1% | Dec 9, 2022 | Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices... |
| CVE-2022-29838 | MEDIUM | 4.6 | 0.3% | Dec 9, 2022 | Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devic... |
| CVE-2022-25630 | MEDIUM | 5.4 | 1.5% | Dec 9, 2022 | An authenticated user can embed malicious content with XSS into the admin group policy page. |
| CVE-2022-25629 | MEDIUM | 5.4 | 0.4% | Dec 9, 2022 | An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation... |
| CVE-2022-23493 | CRITICAL | 9.1 | 0.9% | Dec 9, 2022 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc... |
| CVE-2022-23484 | CRITICAL | 9.8 | 0.7% | Dec 9, 2022 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc... |
| CVE-2022-23483 | CRITICAL | 9.1 | 0.8% | Dec 9, 2022 | xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now