2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43333 | CRITICAL | 9.8 | 1.6% | Dec 1, 2022 | Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the... |
| CVE-2022-35120 | HIGH | 8.8 | 0.2% | Dec 1, 2022 | IXPdata EasyInstall 6.6.14725 contains an access control issue. |
| CVE-2022-42718 | HIGH | 7.8 | 0.2% | Dec 1, 2022 | Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authen... |
| CVE-2022-41971 | MEDIUM | 6.5 | 0.8% | Dec 1, 2022 | Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, a... |
| CVE-2022-41970 | MEDIUM | 5.3 | 0.6% | Dec 1, 2022 | Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares ... |
| CVE-2022-41969 | LOW | 2.7 | 0.8% | Dec 1, 2022 | Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no pas... |
| CVE-2022-41968 | MEDIUM | 5.3 | 0.8% | Dec 1, 2022 | Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths ar... |
| CVE-2022-23737 | MEDIUM | 6.5 | 0.7% | Dec 1, 2022 | An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improp... |
| CVE-2022-43901 | MEDIUM | 5.5 | 0.2% | Dec 1, 2022 | IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticate... |
| CVE-2022-43900 | MEDIUM | 6.5 | 0.2% | Dec 1, 2022 | IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A loca... |
| CVE-2022-41297 | MEDIUM | 6.5 | 0.2% | Dec 1, 2022 | IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou... |
| CVE-2022-3713 | HIGH | 8.8 | 0.7% | Dec 1, 2022 | A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall relea... |
| CVE-2022-3711 | MEDIUM | 4.3 | 0.7% | Dec 1, 2022 | A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in ... |
| CVE-2022-3710 | LOW | 2.7 | 0.7% | Dec 1, 2022 | A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database conten... |
| CVE-2022-3709 | HIGH | 8.4 | 0.8% | Dec 1, 2022 | A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sopho... |
| CVE-2022-3696 | HIGH | 7.2 | 1.1% | Dec 1, 2022 | A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older tha... |
| CVE-2022-3226 | HIGH | 7.2 | 1.7% | Dec 1, 2022 | An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall... |
| CVE-2022-2969 | HIGH | 7.5 | 2.3% | Dec 1, 2022 | Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname int... |
| CVE-2022-29837 | HIGH | 7.8 | 0.2% | Dec 1, 2022 | A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which c... |
| CVE-2022-4257 | CRITICAL | 9.8 | 43.9% | Dec 1, 2022 | A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknow... |
| CVE-2022-37017 | HIGH | 7.5 | 1.1% | Dec 1, 2022 | Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Contr... |
| CVE-2022-37016 | CRITICAL | 9.8 | 0.7% | Dec 1, 2022 | Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type... |
| CVE-2022-30528 | CRITICAL | 9.8 | 1.2% | Dec 1, 2022 | SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attacke... |
| CVE-2022-28607 | HIGH | 7.5 | 0.8% | Dec 1, 2022 | An issue was discovered in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers t... |
| CVE-2022-3270 | CRITICAL | 9.8 | 1.1% | Dec 1, 2022 | In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which c... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now