2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45939 | HIGH | 7.8 | 0.6% | Nov 28, 2022 | GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, ... |
| CVE-2022-45934 | HIGH | 7.8 | 0.8% | Nov 27, 2022 | An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an intege... |
| CVE-2022-43705 | CRITICAL | 9.1 | 0.4% | Nov 27, 2022 | In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was i... |
| CVE-2022-45933 | CRITICAL | 9.8 | 51.7% | Nov 27, 2022 | KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does n... |
| CVE-2022-45932 | HIGH | 7.5 | 0.6% | Nov 27, 2022 | A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/... |
| CVE-2022-45931 | HIGH | 7.5 | 0.5% | Nov 27, 2022 | A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/... |
| CVE-2022-45930 | HIGH | 7.5 | 0.7% | Nov 27, 2022 | A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/... |
| CVE-2022-45919 | HIGH | 7 | 0.3% | Nov 27, 2022 | An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c, a use-after-free... |
| CVE-2022-45914 | MEDIUM | 6.5 | 0.7% | Nov 27, 2022 | The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-21... |
| CVE-2022-24999 | HIGH | 7.5 | 14.7% | Nov 26, 2022 | qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for... |
| CVE-2022-45909 | CRITICAL | 9.1 | 1.0% | Nov 26, 2022 | drachtio-server before 0.8.19 has a heap-based buffer over-read via a long Request-URI in an INVITE request. |
| CVE-2022-45908 | CRITICAL | 9.8 | 1.3% | Nov 26, 2022 | In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on ... |
| CVE-2022-45907 | CRITICAL | 9.8 | 1.2% | Nov 26, 2022 | In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is ... |
| CVE-2022-45225 | MEDIUM | 6.1 | 0.5% | Nov 25, 2022 | Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index... |
| CVE-2022-44844 | CRITICAL | 9.8 | 2.0% | Nov 25, 2022 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass paramete... |
| CVE-2022-44843 | CRITICAL | 9.8 | 2.0% | Nov 25, 2022 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port paramete... |
| CVE-2022-39333 | MEDIUM | 6.1 | 0.9% | Nov 25, 2022 | Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in... |
| CVE-2022-39332 | MEDIUM | 5.4 | 0.9% | Nov 25, 2022 | Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in... |
| CVE-2022-39325 | MEDIUM | 6.1 | 0.5% | Nov 25, 2022 | BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scrip... |
| CVE-2022-45152 | CRITICAL | 9.1 | 1.4% | Nov 25, 2022 | A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient valid... |
| CVE-2022-41954 | LOW | 3.3 | 0.2% | Nov 25, 2022 | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-lik... |
| CVE-2022-41926 | MEDIUM | 5.5 | 0.3% | Nov 25, 2022 | Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the rece... |
| CVE-2022-41158 | CRITICAL | 9.8 | 1.8% | Nov 25, 2022 | Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A... |
| CVE-2022-41157 | CRITICAL | 9.8 | 0.5% | Nov 25, 2022 | A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vul... |
| CVE-2022-41156 | HIGH | 7.8 | 0.2% | Nov 25, 2022 | Remote code execution vulnerability due to insufficient verification of URLs, etc. in OndiskPlayerAgent. A remote attack... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now