2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44363 | CRITICAL | 9.8 | 0.8% | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo. |
| CVE-2022-44362 | CRITICAL | 9.8 | 0.9% | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule. |
| CVE-2022-44348 | HIGH | 7.2 | 0.7% | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/update_status.php?id=. |
| CVE-2022-44347 | HIGH | 7.2 | 0.7% | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=inquiries/view_inquiry&id=. |
| CVE-2022-44345 | HIGH | 7.2 | 0.7% | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=quotes/view_quote&id=. |
| CVE-2022-44277 | HIGH | 7.2 | 0.7% | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/classes/Master.php?f=delete_product. |
| CVE-2022-3591 | HIGH | 7.8 | 0.4% | Dec 2, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0789. |
| CVE-2022-4271 | MEDIUM | 5.4 | 0.7% | Dec 2, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4. |
| CVE-2022-45483 | MEDIUM | 5.9 | 0.4% | Dec 2, 2022 | Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all dat... |
| CVE-2022-45482 | CRITICAL | 9.8 | 1.3% | Dec 2, 2022 | Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticat... |
| CVE-2022-45480 | MEDIUM | 5.9 | 0.4% | Dec 2, 2022 | PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected devi... |
| CVE-2022-43272 | HIGH | 7.5 | 1.6% | Dec 2, 2022 | DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object. |
| CVE-2022-46159 | MEDIUM | 4.3 | 0.6% | Dec 2, 2022 | Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.be... |
| CVE-2022-45215 | MEDIUM | 5.4 | 0.4% | Dec 2, 2022 | A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary ... |
| CVE-2022-46366 | CRITICAL | 9.8 | 3.6% | Dec 2, 2022 | Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to... |
| CVE-2022-4270 | LOW | 2.6 | 0.5% | Dec 2, 2022 | Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permi... |
| CVE-2022-2808 | HIGH | 8.8 | 0.7% | Dec 2, 2022 | Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows... |
| CVE-2022-2807 | CRITICAL | 9.8 | 0.6% | Dec 2, 2022 | SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects... |
| CVE-2022-45562 | HIGH | 8.8 | 1.0% | Dec 2, 2022 | Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system s... |
| CVE-2022-44930 | CRITICAL | 9.8 | 2.5% | Dec 2, 2022 | D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function. |
| CVE-2022-44929 | CRITICAL | 9.8 | 1.1% | Dec 2, 2022 | An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitr... |
| CVE-2022-44928 | CRITICAL | 9.8 | 2.7% | Dec 2, 2022 | D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function. |
| CVE-2022-43325 | CRITICAL | 9.8 | 3.2% | Dec 2, 2022 | An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MP... |
| CVE-2022-44212 | MEDIUM | 5.9 | 0.6% | Dec 1, 2022 | In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel. |
| CVE-2022-44211 | HIGH | 7.4 | 0.6% | Dec 1, 2022 | In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now