2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44279 | MEDIUM | 6.1 | 0.6% | Nov 29, 2022 | Garage Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /garage/php_action/createBrand.php. |
| CVE-2022-4172 | MEDIUM | 6.5 | 0.4% | Nov 29, 2022 | An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of ... |
| CVE-2022-4144 | MEDIUM | 6.5 | 0.3% | Nov 29, 2022 | An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not ... |
| CVE-2022-46150 | MEDIUM | 4.3 | 0.5% | Nov 29, 2022 | Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14... |
| CVE-2022-46152 | HIGH | 8.8 | 0.5% | Nov 29, 2022 | OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior t... |
| CVE-2022-46148 | MEDIUM | 5.4 | 0.5% | Nov 29, 2022 | Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.b... |
| CVE-2022-44356 | HIGH | 7.5 | 2.8% | Nov 29, 2022 | WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access contr... |
| CVE-2022-44355 | MEDIUM | 6.1 | 1.6% | Nov 29, 2022 | SolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php. |
| CVE-2022-44354 | CRITICAL | 9.8 | 2.1% | Nov 29, 2022 | SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. |
| CVE-2022-25848 | HIGH | 7.5 | 1.0% | Nov 29, 2022 | This affects all versions of package static-dev-server. This is because when paths from users to the root directory are ... |
| CVE-2022-21126 | HIGH | 7.8 | 0.7% | Nov 29, 2022 | The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insec... |
| CVE-2022-45343 | HIGH | 7.8 | 0.3% | Nov 29, 2022 | GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at /g... |
| CVE-2022-44635 | HIGH | 8.8 | 68.8% | Nov 29, 2022 | Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in ... |
| CVE-2022-46146 | HIGH | 8.8 | 1.2% | Nov 29, 2022 | Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has a... |
| CVE-2022-36433 | MEDIUM | 6.1 | 0.6% | Nov 29, 2022 | The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript c... |
| CVE-2022-4202 | HIGH | 8.8 | 0.8% | Nov 29, 2022 | A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-rev490-g68064e101-master. Affected is th... |
| CVE-2022-45329 | HIGH | 7.5 | 0.8% | Nov 29, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allo... |
| CVE-2022-43326 | HIGH | 7.5 | 0.7% | Nov 29, 2022 | An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node... |
| CVE-2022-41568 | HIGH | 7.5 | 0.6% | Nov 29, 2022 | LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat. |
| CVE-2022-40799 | HIGH | 8.8 | 31.3% | Nov 29, 2022 | Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS l... |
| CVE-2022-45204 | MEDIUM | 5.5 | 0.3% | Nov 29, 2022 | GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a memory leak via the function dimC_box_read at isomedi... |
| CVE-2022-45202 | HIGH | 7.8 | 0.3% | Nov 29, 2022 | GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isom... |
| CVE-2022-44038 | CRITICAL | 9.8 | 1.6% | Nov 29, 2022 | Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunn... |
| CVE-2022-44037 | HIGH | 8.8 | 0.6% | Nov 29, 2022 | An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V... |
| CVE-2022-42109 | CRITICAL | 9.8 | 1.1% | Nov 29, 2022 | Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shop... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now