2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45536 | MEDIUM | 4.9 | 0.8% | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php.... |
| CVE-2022-45535 | MEDIUM | 4.9 | 0.8% | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. ... |
| CVE-2022-45529 | MEDIUM | 4.9 | 0.7% | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\incl... |
| CVE-2022-45331 | HIGH | 7.5 | 0.8% | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnera... |
| CVE-2022-45330 | HIGH | 7.5 | 0.8% | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This... |
| CVE-2022-39397 | MEDIUM | 4.3 | 0.4% | Nov 22, 2022 | aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret wi... |
| CVE-2022-41919 | HIGH | 8.8 | 0.4% | Nov 22, 2022 | Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Ty... |
| CVE-2022-39199 | MEDIUM | 5.9 | 0.3% | Nov 22, 2022 | immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to disting... |
| CVE-2022-2791 | HIGH | 7.8 | 0.2% | Nov 22, 2022 | Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File w... |
| CVE-2022-4116 | CRITICAL | 9.8 | 32.5% | Nov 22, 2022 | A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by... |
| CVE-2022-41943 | HIGH | 7.2 | 0.9% | Nov 22, 2022 | sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver ... |
| CVE-2022-41942 | HIGH | 7.8 | 1.5% | Nov 22, 2022 | Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the... |
| CVE-2022-40228 | MEDIUM | 5.4 | 0.3% | Nov 22, 2022 | IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.... |
| CVE-2022-3500 | MEDIUM | 5.1 | 0.2% | Nov 22, 2022 | A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled ... |
| CVE-2022-43212 | CRITICAL | 9.8 | 0.9% | Nov 22, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOr... |
| CVE-2022-41950 | HIGH | 7.8 | 0.4% | Nov 22, 2022 | super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerabilit... |
| CVE-2022-39070 | CRITICAL | 9.8 | 0.8% | Nov 22, 2022 | There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote a... |
| CVE-2022-39067 | MEDIUM | 6.5 | 0.6% | Nov 22, 2022 | There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interf... |
| CVE-2022-39066 | HIGH | 8.8 | 26.5% | Nov 22, 2022 | There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phon... |
| CVE-2022-44737 | HIGH | 8.8 | 0.3% | Nov 22, 2022 | Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plu... |
| CVE-2022-41952 | MEDIUM | 5.3 | 0.8% | Nov 22, 2022 | Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs... |
| CVE-2022-44808 | CRITICAL | 9.8 | 3.8% | Nov 22, 2022 | A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an... |
| CVE-2022-44807 | CRITICAL | 9.8 | 1.2% | Nov 22, 2022 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString. |
| CVE-2022-44806 | CRITICAL | 9.8 | 1.2% | Nov 22, 2022 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow. |
| CVE-2022-44804 | CRITICAL | 9.8 | 1.2% | Nov 22, 2022 | D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now