2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44951 | MEDIUM | 5.4 | 0.9% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab f... |
| CVE-2022-44950 | MEDIUM | 5.4 | 0.9% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field func... |
| CVE-2022-44949 | MEDIUM | 5.4 | 0.9% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field func... |
| CVE-2022-44948 | MEDIUM | 5.4 | 0.9% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group fea... |
| CVE-2022-44947 | MEDIUM | 5.4 | 1.0% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feat... |
| CVE-2022-44946 | MEDIUM | 5.4 | 1.0% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function ... |
| CVE-2022-44945 | CRITICAL | 9.8 | 0.9% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter. |
| CVE-2022-44944 | MEDIUM | 5.4 | 1.0% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement f... |
| CVE-2022-44291 | CRITICAL | 9.8 | 3.7% | Dec 2, 2022 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php. |
| CVE-2022-44290 | CRITICAL | 9.8 | 3.7% | Dec 2, 2022 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php... |
| CVE-2022-3086 | HIGH | 7.6 | 0.3% | Dec 2, 2022 | Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers ... |
| CVE-2022-2642 | HIGH | 7.5 | 0.6% | Dec 2, 2022 | Horner Automation’s RCC 972 firmware version 15.40 contains global variables. This could allow an attacker to read out s... |
| CVE-2022-2641 | CRITICAL | 9.8 | 0.5% | Dec 2, 2022 | Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an a... |
| CVE-2022-2640 | HIGH | 7.5 | 0.2% | Dec 2, 2022 | The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulne... |
| CVE-2022-46167 | HIGH | 8.8 | 0.9% | Dec 2, 2022 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed ... |
| CVE-2022-3520 | CRITICAL | 9.8 | 1.0% | Dec 2, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765. |
| CVE-2022-46145 | CRITICAL | 9.8 | 1.2% | Dec 2, 2022 | authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized ... |
| CVE-2022-45672 | HIGH | 7.5 | 9.1% | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the formWx3AuthorizeSet function. |
| CVE-2022-45671 | HIGH | 7.5 | 0.8% | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formSetAppFilterRu... |
| CVE-2022-45670 | HIGH | 7.5 | 0.8% | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing func... |
| CVE-2022-45669 | HIGH | 7.5 | 0.8% | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterGet... |
| CVE-2022-45668 | MEDIUM | 6.5 | 0.3% | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot. |
| CVE-2022-45667 | MEDIUM | 6.5 | 0.3% | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet. |
| CVE-2022-45664 | HIGH | 7.5 | 0.8% | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDget functi... |
| CVE-2022-45663 | HIGH | 7.5 | 0.8% | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now