2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23466 | MEDIUM | 5.4 | 0.4% | Dec 6, 2022 | teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to... |
| CVE-2022-45326 | MEDIUM | 4.9 | 1.1% | Dec 6, 2022 | An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote... |
| CVE-2022-40680 | MEDIUM | 5.4 | 0.4% | Dec 6, 2022 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.1... |
| CVE-2022-38379 | MEDIUM | 5.4 | 0.4% | Dec 6, 2022 | Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allo... |
| CVE-2022-35843 | CRITICAL | 9.8 | 0.9% | Dec 6, 2022 | An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.... |
| CVE-2022-33876 | MEDIUM | 6.5 | 0.7% | Dec 6, 2022 | Multiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through ... |
| CVE-2022-33875 | HIGH | 8.8 | 0.7% | Dec 6, 2022 | An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiA... |
| CVE-2022-30305 | HIGH | 7.5 | 0.6% | Dec 6, 2022 | An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1... |
| CVE-2022-46382 | HIGH | 8.8 | 0.6% | Dec 6, 2022 | RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 h... |
| CVE-2022-44289 | HIGH | 8.8 | 2.9% | Dec 6, 2022 | Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell. |
| CVE-2022-43363 | MEDIUM | 6.1 | 0.4% | Dec 6, 2022 | Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties... |
| CVE-2022-41325 | HIGH | 7.8 | 0.6% | Dec 6, 2022 | An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user... |
| CVE-2022-38123 | HIGH | 7.2 | 0.7% | Dec 6, 2022 | Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrato... |
| CVE-2022-46383 | CRITICAL | 9.8 | 0.7% | Dec 6, 2022 | RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 h... |
| CVE-2022-40209 | MEDIUM | 6.1 | 0.4% | Dec 6, 2022 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xylus Themes WP Smart Import plugin <= 1.0.2 on WordPress. |
| CVE-2022-4300 | HIGH | 8.8 | 0.8% | Dec 6, 2022 | A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the f... |
| CVE-2022-4296 | MEDIUM | 5.5 | 0.3% | Dec 6, 2022 | A vulnerability classified as problematic has been found in TP-Link TL-WR740N. Affected is an unknown function of the co... |
| CVE-2022-42782 | MEDIUM | 5.5 | 0.1% | Dec 6, 2022 | In wlan driver, there is a possible missing permission check, This could lead to local information disclosure. |
| CVE-2022-42781 | MEDIUM | 5.5 | 0.1% | Dec 6, 2022 | In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services. |
| CVE-2022-42780 | MEDIUM | 5.5 | 0.1% | Dec 6, 2022 | In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services. |
| CVE-2022-42779 | MEDIUM | 5.5 | 0.1% | Dec 6, 2022 | In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services. |
| CVE-2022-42778 | HIGH | 7.8 | 0.1% | Dec 6, 2022 | In windows manager service, there is a missing permission check. This could lead to set up windows manager service with ... |
| CVE-2022-42777 | HIGH | 7.8 | 0.1% | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service wit... |
| CVE-2022-42776 | HIGH | 7.8 | 0.1% | Dec 6, 2022 | In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no addit... |
| CVE-2022-42775 | MEDIUM | 5.5 | 0.1% | Dec 6, 2022 | In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of serv... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now