2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44373 | HIGH | 8.8 | 1.4% | Dec 7, 2022 | A stack overflow vulnerability exists in TrendNet Wireless AC Easy-Upgrader TEW-820AP (Version v1.0R, firmware version 1... |
| CVE-2022-44351 | CRITICAL | 9.8 | 0.9% | Dec 7, 2022 | Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php. |
| CVE-2022-43581 | HIGH | 8.8 | 0.7% | Dec 7, 2022 | IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 i... |
| CVE-2022-44393 | HIGH | 7.2 | 0.8% | Dec 7, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=. |
| CVE-2022-44371 | CRITICAL | 9.8 | 1.3% | Dec 7, 2022 | hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE). |
| CVE-2022-44361 | MEDIUM | 5.4 | 0.4% | Dec 7, 2022 | An issue was discovered in ZZCMS 2022. There is a cross-site scripting (XSS) vulnerability in admin/ad_list.php. |
| CVE-2022-41735 | MEDIUM | 6.1 | 0.4% | Dec 7, 2022 | IBM Business Process Manager 21.0.1 through 21.0.3.1, 20.0.0.1 through 20.0.0.2 19.0.0.1 through 19.0.0.3 is vulnerable ... |
| CVE-2022-41720 | HIGH | 7.5 | 1.2% | Dec 7, 2022 | On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide ... |
| CVE-2022-45217 | MEDIUM | 5.4 | 0.5% | Dec 7, 2022 | A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary ... |
| CVE-2022-45910 | MEDIUM | 5.3 | 1.5% | Dec 7, 2022 | Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory an... |
| CVE-2022-42458 | CRITICAL | 9.8 | 1.1% | Dec 7, 2022 | Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a ... |
| CVE-2022-40966 | HIGH | 8.8 | 0.3% | Dec 7, 2022 | Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass aut... |
| CVE-2022-39044 | MEDIUM | 6.8 | 0.3% | Dec 7, 2022 | Hidden functionality vulnerability in multiple Buffalo network devices allows a network-adjacent attacker with an admini... |
| CVE-2022-34840 | MEDIUM | 6.5 | 0.2% | Dec 7, 2022 | Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to al... |
| CVE-2022-46742 | CRITICAL | 9.8 | 1.1% | Dec 7, 2022 | Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution. |
| CVE-2022-46741 | CRITICAL | 9.1 | 0.7% | Dec 7, 2022 | Out-of-bounds read in gather_tree in PaddlePaddle before 2.4. |
| CVE-2022-4322 | HIGH | 7.2 | 0.8% | Dec 7, 2022 | A vulnerability, which was classified as critical, was found in maku-boot up to 2.2.0. This affects the function doExecu... |
| CVE-2022-45122 | MEDIUM | 6.1 | 0.5% | Dec 7, 2022 | Cross-site scripting vulnerability in Movable Type Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Ty... |
| CVE-2022-45113 | MEDIUM | 6.5 | 0.6% | Dec 7, 2022 | Improper validation of syntactic correctness of input vulnerability exist in Movable Type series. Having a user to acces... |
| CVE-2022-44620 | HIGH | 8.8 | 0.9% | Dec 7, 2022 | Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earli... |
| CVE-2022-44608 | HIGH | 7.5 | 0.9% | Dec 7, 2022 | Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated at... |
| CVE-2022-44606 | HIGH | 8.8 | 1.5% | Dec 7, 2022 | OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier ... |
| CVE-2022-43668 | MEDIUM | 6.1 | 0.4% | Dec 7, 2022 | Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript co... |
| CVE-2022-43667 | HIGH | 7.8 | 0.3% | Dec 7, 2022 | Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disc... |
| CVE-2022-43660 | HIGH | 7.2 | 1.0% | Dec 7, 2022 | Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authentic... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now