2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1471 | CRITICAL | 9.8 | 99.6% | Dec 1, 2022 | SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing ... |
| CVE-2022-4221 | CRITICAL | 9.8 | 4.8% | Dec 1, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25... |
| CVE-2022-45050 | MEDIUM | 6.1 | 0.4% | Dec 1, 2022 | A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's br... |
| CVE-2022-4253 | MEDIUM | 5.4 | 0.4% | Dec 1, 2022 | A vulnerability was found in SourceCodester Canteen Management System. It has been declared as problematic. This vulnera... |
| CVE-2022-4252 | MEDIUM | 6.1 | 0.4% | Dec 1, 2022 | A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affec... |
| CVE-2022-4251 | MEDIUM | 5.4 | 0.4% | Dec 1, 2022 | A vulnerability was found in Movie Ticket Booking System and classified as problematic. Affected by this issue is some u... |
| CVE-2022-4250 | MEDIUM | 6.1 | 0.4% | Dec 1, 2022 | A vulnerability has been found in Movie Ticket Booking System and classified as problematic. Affected by this vulnerabil... |
| CVE-2022-4249 | MEDIUM | 6.1 | 0.4% | Dec 1, 2022 | A vulnerability, which was classified as problematic, was found in Movie Ticket Booking System. Affected is an unknown f... |
| CVE-2022-4248 | CRITICAL | 9.8 | 0.5% | Dec 1, 2022 | A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects som... |
| CVE-2022-4247 | CRITICAL | 9.8 | 0.5% | Dec 1, 2022 | A vulnerability classified as critical was found in Movie Ticket Booking System. This vulnerability affects unknown code... |
| CVE-2022-4246 | HIGH | 7.5 | 0.7% | Dec 1, 2022 | A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the compone... |
| CVE-2022-36431 | CRITICAL | 9.8 | 1.1% | Dec 1, 2022 | An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to... |
| CVE-2022-45640 | HIGH | 7.5 | 1.0% | Dec 1, 2022 | Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local). |
| CVE-2022-45045 | HIGH | 8.8 | 1.2% | Dec 1, 2022 | Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C74311... |
| CVE-2022-44262 | CRITICAL | 9.8 | 1.5% | Dec 1, 2022 | ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE). |
| CVE-2022-40849 | MEDIUM | 5.4 | 0.4% | Dec 1, 2022 | ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vul... |
| CVE-2022-40489 | HIGH | 8.8 | 0.3% | Dec 1, 2022 | ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrato... |
| CVE-2022-40204 | MEDIUM | 5.4 | 0.3% | Dec 1, 2022 | A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via t... |
| CVE-2022-46162 | CRITICAL | 9.8 | 1.1% | Nov 30, 2022 | discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rend... |
| CVE-2022-46156 | LOW | 3.3 | 0.5% | Nov 30, 2022 | The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes ... |
| CVE-2022-23746 | HIGH | 7.5 | 0.6% | Nov 30, 2022 | The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the por... |
| CVE-2022-44296 | HIGH | 7.2 | 0.7% | Nov 30, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/quotes/manage_remark.php?id=. |
| CVE-2022-44295 | HIGH | 7.2 | 0.7% | Nov 30, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=. |
| CVE-2022-44294 | HIGH | 7.2 | 0.7% | Nov 30, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/manage_service&id=. |
| CVE-2022-4234 | MEDIUM | 6.1 | 0.4% | Nov 30, 2022 | A vulnerability was found in SourceCodester Canteen Management System. It has been rated as problematic. This issue affe... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now