2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23044 | HIGH | 8.8 | 0.4% | Nov 25, 2022 | Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended action... |
| CVE-2022-45040 | MEDIUM | 5.4 | 0.4% | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to exec... |
| CVE-2022-45039 | HIGH | 7.2 | 1.0% | Nov 25, 2022 | An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbi... |
| CVE-2022-45038 | MEDIUM | 5.4 | 1.0% | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute ar... |
| CVE-2022-45037 | MEDIUM | 5.4 | 1.0% | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbi... |
| CVE-2022-45036 | MEDIUM | 5.4 | 0.5% | Nov 25, 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute ... |
| CVE-2022-44411 | HIGH | 7.5 | 0.4% | Nov 25, 2022 | Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers t... |
| CVE-2022-38377 | LOW | 2.7 | 0.5% | Nov 25, 2022 | An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.... |
| CVE-2022-37720 | CRITICAL | 9 | 1.0% | Nov 25, 2022 | Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an aut... |
| CVE-2022-38767 | HIGH | 7.5 | 1.0% | Nov 25, 2022 | An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius serv... |
| CVE-2022-38166 | HIGH | 7.5 | 0.7% | Nov 25, 2022 | In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dl... |
| CVE-2022-4141 | HIGH | 7.8 | 0.4% | Nov 25, 2022 | Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in ... |
| CVE-2022-4091 | MEDIUM | 6.1 | 0.4% | Nov 25, 2022 | A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affec... |
| CVE-2022-36133 | CRITICAL | 9.1 | 0.7% | Nov 25, 2022 | The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication ... |
| CVE-2022-40282 | HIGH | 8.8 | 4.0% | Nov 25, 2022 | The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authent... |
| CVE-2022-2721 | HIGH | 7.5 | 0.6% | Nov 25, 2022 | In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive t... |
| CVE-2022-45888 | MEDIUM | 6.4 | 0.7% | Nov 25, 2022 | An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use... |
| CVE-2022-45887 | MEDIUM | 4.7 | 0.3% | Nov 25, 2022 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak bec... |
| CVE-2022-45886 | HIGH | 7 | 0.3% | Nov 25, 2022 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_net.c has a .disconnect versus dvb... |
| CVE-2022-45885 | HIGH | 7 | 0.3% | Nov 25, 2022 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition th... |
| CVE-2022-45884 | HIGH | 7 | 0.3% | Nov 25, 2022 | An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related... |
| CVE-2022-4135 | CRITICAL | 9.6 | 31.9% | Nov 25, 2022 | Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the r... |
| CVE-2022-29833 | MEDIUM | 6.5 | 1.0% | Nov 25, 2022 | Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and late... |
| CVE-2022-29832 | MEDIUM | 6.5 | 0.6% | Nov 25, 2022 | Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions... |
| CVE-2022-29831 | HIGH | 7.5 | 1.3% | Nov 25, 2022 | Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z all... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now