2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38337 | CRITICAL | 9.1 | 0.7% | Dec 6, 2022 | When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this... |
| CVE-2022-38336 | HIGH | 8.1 | 0.8% | Dec 6, 2022 | An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP... |
| CVE-2022-46464 | — | — | — | Dec 5, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-45990 | MEDIUM | 6.1 | 0.5% | Dec 5, 2022 | A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attacker... |
| CVE-2022-45769 | MEDIUM | 6.1 | 0.5% | Dec 5, 2022 | A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts o... |
| CVE-2022-45020 | HIGH | 8.8 | 0.6% | Dec 5, 2022 | Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /ruko... |
| CVE-2022-45019 | HIGH | 7.5 | 0.8% | Dec 5, 2022 | SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter. |
| CVE-2022-43706 | MEDIUM | 5.4 | 0.4% | Dec 5, 2022 | Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users wit... |
| CVE-2022-45912 | HIGH | 7.2 | 1.1% | Dec 5, 2022 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUplo... |
| CVE-2022-43557 | MEDIUM | 5.3 | 0.2% | Dec 5, 2022 | The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, th... |
| CVE-2022-43556 | MEDIUM | 6.1 | 0.6% | Dec 5, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field ... |
| CVE-2022-43553 | HIGH | 8.8 | 1.0% | Dec 5, 2022 | A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with ... |
| CVE-2022-43549 | CRITICAL | 9.8 | 0.7% | Dec 5, 2022 | Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechani... |
| CVE-2022-43548 | HIGH | 8.1 | 14.0% | Dec 5, 2022 | A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insuffic... |
| CVE-2022-40259 | CRITICAL | 9.8 | 0.6% | Dec 5, 2022 | MegaRAC Default Credentials Vulnerability |
| CVE-2022-40242 | CRITICAL | 9.8 | 0.7% | Dec 5, 2022 | MegaRAC Default Credentials Vulnerability |
| CVE-2022-35260 | MEDIUM | 6.5 | 1.8% | Dec 5, 2022 | curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white sp... |
| CVE-2022-35259 | HIGH | 7.8 | 0.7% | Dec 5, 2022 | XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute... |
| CVE-2022-35258 | HIGH | 7.5 | 2.5% | Dec 5, 2022 | An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in vers... |
| CVE-2022-35256 | MEDIUM | 6.5 | 2.6% | Dec 5, 2022 | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated wit... |
| CVE-2022-35255 | CRITICAL | 9.1 | 1.9% | Dec 5, 2022 | A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretK... |
| CVE-2022-35254 | HIGH | 7.5 | 2.5% | Dec 5, 2022 | An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in vers... |
| CVE-2022-32224 | CRITICAL | 9.8 | 2.4% | Dec 5, 2022 | A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.... |
| CVE-2022-32221 | CRITICAL | 9.8 | 4.3% | Dec 5, 2022 | When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data t... |
| CVE-2022-30123 | CRITICAL | 10 | 1.8% | Dec 5, 2022 | A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now