2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44938 | CRITICAL | 9.8 | 1.0% | Dec 8, 2022 | Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brut... |
| CVE-2022-41717 | MEDIUM | 5.3 | 5.6% | Dec 8, 2022 | An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contai... |
| CVE-2022-4366 | HIGH | 7.5 | 0.7% | Dec 8, 2022 | Missing Authorization in GitHub repository lirantal/daloradius prior to master branch. |
| CVE-2022-46831 | MEDIUM | 4.9 | 0.4% | Dec 8, 2022 | In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allo... |
| CVE-2022-46830 | MEDIUM | 5.3 | 0.5% | Dec 8, 2022 | In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning. |
| CVE-2022-46829 | HIGH | 8.8 | 0.4% | Dec 8, 2022 | In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented. |
| CVE-2022-46828 | HIGH | 7.8 | 0.3% | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible. |
| CVE-2022-46827 | MEDIUM | 5.5 | 0.2% | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was po... |
| CVE-2022-46826 | MEDIUM | 5.5 | 0.2% | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a pa... |
| CVE-2022-46825 | LOW | 3.3 | 0.1% | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects. |
| CVE-2022-46824 | HIGH | 7.8 | 0.2% | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible. |
| CVE-2022-40939 | MEDIUM | 4.9 | 0.4% | Dec 8, 2022 | In certain Secustation products the administrator account password can be read. This affects V2.5.5.3116-S50-SMA-B201711... |
| CVE-2022-38599 | MEDIUM | 6.5 | 0.8% | Dec 8, 2022 | Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user... |
| CVE-2022-4123 | LOW | 3.3 | 0.2% | Dec 8, 2022 | A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path ... |
| CVE-2022-4122 | MEDIUM | 5.3 | 0.8% | Dec 8, 2022 | A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore r... |
| CVE-2022-45877 | MEDIUM | 5.3 | 0.2% | Dec 8, 2022 | OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text dur... |
| CVE-2022-45525 | HIGH | 7.5 | 0.9% | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInf... |
| CVE-2022-45524 | HIGH | 7.5 | 0.9% | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave. |
| CVE-2022-45523 | HIGH | 7.5 | 0.9% | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im. |
| CVE-2022-45522 | HIGH | 7.5 | 0.9% | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter. |
| CVE-2022-45521 | HIGH | 7.5 | 0.9% | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter. |
| CVE-2022-45520 | HIGH | 7.5 | 0.9% | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting. |
| CVE-2022-45519 | HIGH | 7.5 | 0.9% | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter. |
| CVE-2022-45518 | HIGH | 7.5 | 0.9% | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SetIpBind. |
| CVE-2022-45517 | HIGH | 7.5 | 0.9% | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now