2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36111 | MEDIUM | 5.3 | 0.4% | Nov 23, 2022 | immudb is a database with built-in cryptographic proof and verification. In versions prior to 1.4.1, a malicious immudb ... |
| CVE-2022-23740 | HIGH | 8.8 | 1.1% | Nov 23, 2022 | CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterpri... |
| CVE-2022-38115 | MEDIUM | 5.3 | 0.7% | Nov 23, 2022 | Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT |
| CVE-2022-38114 | MEDIUM | 6.1 | 0.5% | Nov 23, 2022 | This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lea... |
| CVE-2022-38113 | MEDIUM | 5.3 | 0.7% | Nov 23, 2022 | This vulnerability discloses build and services versions in the server response header. |
| CVE-2022-35501 | MEDIUM | 5.4 | 0.5% | Nov 23, 2022 | Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the du... |
| CVE-2022-44280 | MEDIUM | 6.5 | 0.8% | Nov 23, 2022 | Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img. |
| CVE-2022-44278 | HIGH | 7.2 | 0.7% | Nov 23, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=. |
| CVE-2022-44260 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the se... |
| CVE-2022-44259 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTim... |
| CVE-2022-44258 | HIGH | 8.8 | 2.3% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTra... |
| CVE-2022-44257 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setO... |
| CVE-2022-44256 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLangua... |
| CVE-2022-44255 | CRITICAL | 9.8 | 2.2% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post d... |
| CVE-2022-44254 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg... |
| CVE-2022-44253 | HIGH | 8.8 | 2.1% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosi... |
| CVE-2022-44252 | CRITICAL | 9.8 | 1.8% | Nov 23, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting ... |
| CVE-2022-44251 | CRITICAL | 9.8 | 1.8% | Nov 23, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function. |
| CVE-2022-44250 | CRITICAL | 9.8 | 1.8% | Nov 23, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg func... |
| CVE-2022-44249 | CRITICAL | 9.8 | 1.8% | Nov 23, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFil... |
| CVE-2022-44139 | CRITICAL | 9.8 | 0.8% | Nov 23, 2022 | Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php. |
| CVE-2022-45151 | MEDIUM | 5.4 | 0.7% | Nov 23, 2022 | The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied dat... |
| CVE-2022-45150 | MEDIUM | 6.1 | 0.7% | Nov 23, 2022 | A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitizati... |
| CVE-2022-45149 | MEDIUM | 5.4 | 0.4% | Nov 23, 2022 | A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course red... |
| CVE-2022-42896 | HIGH | 8.8 | 2.0% | Nov 23, 2022 | There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_c... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now