2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44120 | CRITICAL | 9.8 | 0.7% | Nov 23, 2022 | dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php. |
| CVE-2022-44118 | CRITICAL | 9.8 | 1.6% | Nov 23, 2022 | dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php. |
| CVE-2022-44117 | CRITICAL | 9.8 | 0.7% | Nov 23, 2022 | Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa... |
| CVE-2022-43196 | CRITICAL | 9.1 | 0.7% | Nov 23, 2022 | dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php. |
| CVE-2022-41933 | MEDIUM | 6.5 | 0.4% | Nov 23, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset... |
| CVE-2022-41932 | MEDIUM | 5.3 | 0.5% | Nov 23, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t... |
| CVE-2022-45866 | MEDIUM | 5.3 | 1.3% | Nov 23, 2022 | qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allow... |
| CVE-2022-44140 | HIGH | 8.8 | 0.7% | Nov 23, 2022 | Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component. |
| CVE-2022-41946 | MEDIUM | 5.5 | 0.5% | Nov 23, 2022 | pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStateme... |
| CVE-2022-41935 | MEDIUM | 4.3 | 0.8% | Nov 23, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users without t... |
| CVE-2022-41934 | HIGH | 8.8 | 1.3% | Nov 23, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v... |
| CVE-2022-41931 | HIGH | 8.8 | 1.2% | Nov 23, 2022 | xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injec... |
| CVE-2022-41930 | HIGH | 8.2 | 0.8% | Nov 23, 2022 | org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged ... |
| CVE-2022-41929 | MEDIUM | 4.9 | 0.7% | Nov 23, 2022 | org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorre... |
| CVE-2022-41928 | HIGH | 8.8 | 1.0% | Nov 23, 2022 | XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in A... |
| CVE-2022-41927 | HIGH | 7.4 | 0.3% | Nov 23, 2022 | XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags with... |
| CVE-2022-41925 | HIGH | 8.8 | 0.5% | Nov 23, 2022 | A vulnerability identified in the Tailscale client allows a malicious website to access the peer API, which can then be ... |
| CVE-2022-41924 | CRITICAL | 9.6 | 1.6% | Nov 23, 2022 | A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemo... |
| CVE-2022-41923 | CRITICAL | 9.8 | 1.7% | Nov 23, 2022 | Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to... |
| CVE-2022-41875 | CRITICAL | 9.8 | 1.6% | Nov 23, 2022 | A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via spe... |
| CVE-2022-41922 | CRITICAL | 9.8 | 1.1% | Nov 23, 2022 | `yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize(... |
| CVE-2022-40772 | MEDIUM | 6.5 | 3.0% | Nov 23, 2022 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to a... |
| CVE-2022-40771 | MEDIUM | 4.9 | 3.5% | Nov 23, 2022 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads t... |
| CVE-2022-40304 | HIGH | 7.8 | 6.8% | Nov 23, 2022 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, p... |
| CVE-2022-39833 | HIGH | 7.2 | 2.6% | Nov 23, 2022 | FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and ac... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now