2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-37301 | HIGH | 7.5 | 0.7% | Nov 22, 2022 | A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the contr... |
| CVE-2022-2513 | MEDIUM | 5.5 | 0.1% | Nov 22, 2022 | A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage fun... |
| CVE-2022-41131 | HIGH | 7.8 | 1.8% | Nov 22, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl... |
| CVE-2022-40954 | MEDIUM | 5.5 | 1.4% | Nov 22, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl... |
| CVE-2022-40189 | CRITICAL | 9.8 | 3.9% | Nov 22, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl... |
| CVE-2022-38649 | CRITICAL | 9.8 | 3.2% | Nov 22, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl... |
| CVE-2022-45363 | MEDIUM | 5.4 | 0.4% | Nov 22, 2022 | Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress. |
| CVE-2022-37931 | HIGH | 7.8 | 0.2% | Nov 22, 2022 | A vulnerability in NetBatch-Plus software allows unauthorized access to the application. HPE has provided a workaround... |
| CVE-2022-4111 | MEDIUM | 6.5 | 0.8% | Nov 22, 2022 | Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile... |
| CVE-2022-40602 | CRITICAL | 9.8 | 1.0% | Nov 22, 2022 | A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the ... |
| CVE-2022-36227 | CRITICAL | 9.8 | 1.9% | Nov 22, 2022 | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with ... |
| CVE-2022-35407 | HIGH | 7.8 | 0.2% | Nov 22, 2022 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code... |
| CVE-2022-43685 | HIGH | 8.8 | 0.7% | Nov 22, 2022 | CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request.... |
| CVE-2022-43215 | CRITICAL | 9.8 | 0.9% | Nov 22, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrde... |
| CVE-2022-43214 | CRITICAL | 9.8 | 0.9% | Nov 22, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOr... |
| CVE-2022-41940 | MEDIUM | 6.5 | 1.9% | Nov 22, 2022 | Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc... |
| CVE-2022-41937 | HIGH | 8.1 | 0.7% | Nov 22, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application... |
| CVE-2022-41936 | HIGH | 7.5 | 0.7% | Nov 22, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modificati... |
| CVE-2022-41326 | CRITICAL | 9.8 | 1.4% | Nov 22, 2022 | The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbi... |
| CVE-2022-41223 | MEDIUM | 6.8 | 10.6% | Nov 22, 2022 | The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to ... |
| CVE-2022-40842 | CRITICAL | 9.1 | 0.8% | Nov 22, 2022 | ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php. |
| CVE-2022-40765 | MEDIUM | 6.8 | 10.5% | Nov 22, 2022 | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authen... |
| CVE-2022-36180 | CRITICAL | 9.6 | 1.0% | Nov 22, 2022 | Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fus... |
| CVE-2022-36179 | CRITICAL | 9.8 | 1.1% | Nov 22, 2022 | Fusiondirectory 1.3 suffers from Improper Session Handling. |
| CVE-2022-30529 | HIGH | 7.2 | 1.0% | Nov 22, 2022 | File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now