2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30122 | HIGH | 7.5 | 2.1% | Dec 5, 2022 | A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing compo... |
| CVE-2022-2827 | HIGH | 7.5 | 1.7% | Dec 5, 2022 | AMI MegaRAC User Enumeration Vulnerability |
| CVE-2022-27773 | CRITICAL | 9.8 | 2.6% | Dec 5, 2022 | A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execut... |
| CVE-2022-23143 | MEDIUM | 6.5 | 0.6% | Dec 5, 2022 | ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an a... |
| CVE-2022-46169 | CRITICAL | 9.8 | 99.8% | Dec 5, 2022 | Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management fram... |
| CVE-2022-46164 | CRITICAL | 9.8 | 49.0% | Dec 5, 2022 | NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io me... |
| CVE-2022-45481 | CRITICAL | 9.8 | 1.6% | Dec 5, 2022 | The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute ar... |
| CVE-2022-45479 | CRITICAL | 9.8 | 1.6% | Dec 5, 2022 | PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any... |
| CVE-2022-44039 | CRITICAL | 9.8 | 1.0% | Dec 5, 2022 | Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrit... |
| CVE-2022-42706 | MEDIUM | 4.9 | 1.1% | Dec 5, 2022 | An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified throu... |
| CVE-2022-42705 | MEDIUM | 6.5 | 1.2% | Dec 5, 2022 | A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remo... |
| CVE-2022-37783 | HIGH | 7.5 | 1.0% | Dec 5, 2022 | All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail ad... |
| CVE-2022-37325 | HIGH | 7.5 | 1.0% | Dec 5, 2022 | In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message t... |
| CVE-2022-45771 | HIGH | 8.8 | 1.8% | Dec 5, 2022 | An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary cod... |
| CVE-2022-43516 | CRITICAL | 9.8 | 0.9% | Dec 5, 2022 | A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in... |
| CVE-2022-43097 | MEDIUM | 5.4 | 0.5% | Dec 5, 2022 | Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scriptin... |
| CVE-2022-23467 | MEDIUM | 4.6 | 0.4% | Dec 5, 2022 | OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linu... |
| CVE-2022-4293 | MEDIUM | 5.5 | 0.5% | Dec 5, 2022 | Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804. |
| CVE-2022-4292 | HIGH | 7.8 | 0.7% | Dec 5, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0882. |
| CVE-2022-43515 | CRITICAL | 9.8 | 1.2% | Dec 5, 2022 | Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addre... |
| CVE-2022-3926 | MEDIUM | 6.5 | 0.3% | Dec 5, 2022 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secr... |
| CVE-2022-3909 | MEDIUM | 4.8 | 0.5% | Dec 5, 2022 | The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2022-3907 | HIGH | 7.5 | 0.9% | Dec 5, 2022 | The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API request... |
| CVE-2022-3892 | MEDIUM | 4.8 | 0.5% | Dec 5, 2022 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.2 does not sanitize and escape Client IDs, which ... |
| CVE-2022-3858 | HIGH | 7.2 | 1.0% | Dec 5, 2022 | The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin befo... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now