2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46149 | MEDIUM | 5.4 | 0.9% | Nov 30, 2022 | Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.... |
| CVE-2022-44151 | CRITICAL | 9.8 | 0.9% | Nov 30, 2022 | Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php. |
| CVE-2022-44136 | CRITICAL | 9.8 | 1.1% | Nov 30, 2022 | Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE). |
| CVE-2022-1911 | MEDIUM | 5.3 | 0.6% | Nov 30, 2022 | Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated ... |
| CVE-2022-1606 | MEDIUM | 4.3 | 0.5% | Nov 30, 2022 | Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to rea... |
| CVE-2022-38803 | MEDIUM | 6.8 | 0.6% | Nov 30, 2022 | Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An ... |
| CVE-2022-38802 | MEDIUM | 6.2 | 0.6% | Nov 30, 2022 | Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual ... |
| CVE-2022-38801 | MEDIUM | 5.4 | 0.3% | Nov 30, 2022 | In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cr... |
| CVE-2022-45842 | LOW | 3.7 | 0.3% | Nov 30, 2022 | Unauth. Race Condition vulnerability in WP ULike Plugin <= 4.6.4 on WordPress allows attackers to increase/decrease rati... |
| CVE-2022-26366 | HIGH | 8.8 | 0.3% | Nov 30, 2022 | Cross-Site Request Forgery (CSRF) in AdRotate Banner Manager Plugin <= 5.9 on WordPress. |
| CVE-2022-24441 | HIGH | 8.8 | 0.7% | Nov 30, 2022 | The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince... |
| CVE-2022-22984 | MEDIUM | 6.3 | 3.0% | Nov 30, 2022 | The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.... |
| CVE-2022-4233 | MEDIUM | 6.1 | 0.3% | Nov 30, 2022 | A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as problematic. Affected b... |
| CVE-2022-4232 | CRITICAL | 9.8 | 0.4% | Nov 30, 2022 | A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected i... |
| CVE-2022-4231 | MEDIUM | 5.4 | 0.4% | Nov 30, 2022 | A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue... |
| CVE-2022-4229 | CRITICAL | 9.8 | 0.9% | Nov 30, 2022 | A vulnerability classified as critical was found in SourceCodester Book Store Management System 1.0. This vulnerability ... |
| CVE-2022-4228 | HIGH | 7.5 | 1.2% | Nov 30, 2022 | A vulnerability classified as problematic has been found in SourceCodester Book Store Management System 1.0. This affect... |
| CVE-2022-3859 | MEDIUM | 6.7 | 0.2% | Nov 30, 2022 | An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This all... |
| CVE-2022-4222 | CRITICAL | 9.8 | 0.7% | Nov 30, 2022 | A vulnerability was found in SourceCodester Canteen Management System. It has been rated as critical. This issue affects... |
| CVE-2022-46338 | MEDIUM | 6.5 | 0.7% | Nov 30, 2022 | g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nod... |
| CVE-2022-45869 | MEDIUM | 5.5 | 0.3% | Nov 30, 2022 | A race condition in the x86 KVM subsystem in the Linux kernel through 6.1-rc6 allows guest OS users to cause a denial of... |
| CVE-2022-44097 | CRITICAL | 9.8 | 0.8% | Nov 30, 2022 | Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate pri... |
| CVE-2022-44096 | CRITICAL | 9.8 | 0.8% | Nov 30, 2022 | Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate p... |
| CVE-2022-41413 | MEDIUM | 4.3 | 2.0% | Nov 30, 2022 | perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attack... |
| CVE-2022-41412 | HIGH | 8.6 | 4.1% | Nov 30, 2022 | An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and exec... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now