2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45907 | CRITICAL | 9.8 | 1.2% | Nov 26, 2022 | In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is ... |
| CVE-2022-44844 | CRITICAL | 9.8 | 2.0% | Nov 25, 2022 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass paramete... |
| CVE-2022-44843 | CRITICAL | 9.8 | 2.0% | Nov 25, 2022 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port paramete... |
| CVE-2022-45152 | CRITICAL | 9.1 | 1.4% | Nov 25, 2022 | A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient valid... |
| CVE-2022-41158 | CRITICAL | 9.8 | 1.8% | Nov 25, 2022 | Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A... |
| CVE-2022-41157 | CRITICAL | 9.8 | 0.5% | Nov 25, 2022 | A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vul... |
| CVE-2022-45476 | CRITICAL | 9.8 | 1.0% | Nov 25, 2022 | Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returni... |
| CVE-2022-41705 | CRITICAL | 9.8 | 1.8% | Nov 25, 2022 | Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is... |
| CVE-2022-45207 | CRITICAL | 9.8 | 0.9% | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString. |
| CVE-2022-45206 | CRITICAL | 9.8 | 0.8% | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check. |
| CVE-2022-37721 | CRITICAL | 9 | 0.7% | Nov 25, 2022 | PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a... |
| CVE-2022-37720 | CRITICAL | 9 | 1.0% | Nov 25, 2022 | Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an aut... |
| CVE-2022-36133 | CRITICAL | 9.1 | 0.7% | Nov 25, 2022 | The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication ... |
| CVE-2022-4135 | CRITICAL | 9.6 | 31.9% | Nov 25, 2022 | Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the r... |
| CVE-2022-29830 | CRITICAL | 9.1 | 1.2% | Nov 25, 2022 | Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and M... |
| CVE-2022-2650 | CRITICAL | 9.8 | 0.7% | Nov 24, 2022 | Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2. |
| CVE-2022-4088 | CRITICAL | 9.8 | 0.6% | Nov 24, 2022 | A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some u... |
| CVE-2022-4136 | CRITICAL | 9.8 | 0.9% | Nov 24, 2022 | Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host ... |
| CVE-2022-45872 | CRITICAL | 9.8 | 0.9% | Nov 23, 2022 | iTerm2 before 3.4.18 mishandles a DECRQSS response. |
| CVE-2022-45276 | CRITICAL | 9.8 | 0.8% | Nov 23, 2022 | An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Admi... |
| CVE-2022-44120 | CRITICAL | 9.8 | 0.7% | Nov 23, 2022 | dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php. |
| CVE-2022-44118 | CRITICAL | 9.8 | 1.6% | Nov 23, 2022 | dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php. |
| CVE-2022-44117 | CRITICAL | 9.8 | 0.7% | Nov 23, 2022 | Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa... |
| CVE-2022-43196 | CRITICAL | 9.1 | 0.7% | Nov 23, 2022 | dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php. |
| CVE-2022-41924 | CRITICAL | 9.6 | 1.6% | Nov 23, 2022 | A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemo... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now