2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43509 | HIGH | 7.8 | 0.2% | Dec 7, 2022 | Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure a... |
| CVE-2022-43508 | HIGH | 7.8 | 0.2% | Dec 7, 2022 | Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or... |
| CVE-2022-43468 | HIGH | 7.5 | 0.8% | Dec 7, 2022 | External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and ea... |
| CVE-2022-43464 | HIGH | 8.8 | 1.0% | Dec 7, 2022 | Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier ... |
| CVE-2022-42486 | MEDIUM | 4.8 | 0.6% | Dec 7, 2022 | Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote a... |
| CVE-2022-41994 | MEDIUM | 4.8 | 0.6% | Dec 7, 2022 | Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote aut... |
| CVE-2022-41800 | HIGH | 8.7 | 62.4% | Dec 7, 2022 | In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be... |
| CVE-2022-41783 | MEDIUM | 5.5 | 0.2% | Dec 7, 2022 | tdpServer of TP-Link RE300 V1 improperly processes its input, which may allow an attacker to cause a denial-of-service (... |
| CVE-2022-41622 | HIGH | 8.8 | 88.0% | Dec 7, 2022 | In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. ... |
| CVE-2022-37406 | MEDIUM | 4.8 | 0.6% | Dec 7, 2022 | Cross-site scripting vulnerability in Aficio SP 4210N firmware versions prior to Web Support 1.05 allows a remote authen... |
| CVE-2022-44849 | HIGH | 8.8 | 0.4% | Dec 7, 2022 | A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super ... |
| CVE-2022-45026 | CRITICAL | 9.8 | 1.0% | Dec 7, 2022 | An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary comma... |
| CVE-2022-45025 | CRITICAL | 9.8 | 34.5% | Dec 7, 2022 | Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi... |
| CVE-2022-45010 | CRITICAL | 9.8 | 0.8% | Dec 7, 2022 | Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid paramete... |
| CVE-2022-45009 | HIGH | 7.2 | 1.0% | Dec 7, 2022 | Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/cl... |
| CVE-2022-45008 | MEDIUM | 4.8 | 0.4% | Dec 7, 2022 | Online Leave Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the c... |
| CVE-2022-44942 | HIGH | 8.1 | 0.9% | Dec 7, 2022 | Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function. |
| CVE-2022-44153 | MEDIUM | 6.1 | 0.4% | Dec 7, 2022 | Rapid Software LLC Rapid SCADA 5.8.4 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-45918 | MEDIUM | 6.5 | 1.2% | Dec 7, 2022 | ILIAS before 7.16 allows External Control of File Name or Path. |
| CVE-2022-45917 | MEDIUM | 6.1 | 2.0% | Dec 7, 2022 | ILIAS before 7.16 has an Open Redirect. |
| CVE-2022-45916 | MEDIUM | 5.4 | 0.9% | Dec 7, 2022 | ILIAS before 7.16 allows XSS. |
| CVE-2022-45915 | HIGH | 8.8 | 4.7% | Dec 7, 2022 | ILIAS before 7.16 allows OS Command Injection. |
| CVE-2022-42329 | MEDIUM | 5.5 | 0.2% | Dec 7, 2022 | Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text expl... |
| CVE-2022-42328 | MEDIUM | 5.5 | 0.2% | Dec 7, 2022 | Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text expl... |
| CVE-2022-3643 | MEDIUM | 6.5 | 0.5% | Dec 7, 2022 | Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface res... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now