2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42954 | MEDIUM | 5.4 | 0.3% | Nov 17, 2022 | Keyfactor EJBCA before 7.10.0 allows XSS. |
| CVE-2022-39834 | MEDIUM | 5.4 | 0.3% | Nov 17, 2022 | A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-priv... |
| CVE-2022-36432 | MEDIUM | 5.4 | 0.5% | Nov 17, 2022 | The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers t... |
| CVE-2022-42246 | HIGH | 8.8 | 0.3% | Nov 17, 2022 | Doufox 0.0.4 contains a CSRF vulnerability that can add system administrator account. |
| CVE-2022-42245 | CRITICAL | 9.8 | 0.8% | Nov 17, 2022 | Dreamer CMS 4.0.01 is vulnerable to SQL Injection. |
| CVE-2022-42187 | MEDIUM | 6.1 | 0.4% | Nov 17, 2022 | Hustoj 22.09.22 has a XSS Vulnerability in /admin/problem_judge.php. |
| CVE-2022-40881 | CRITICAL | 9.8 | 29.5% | Nov 17, 2022 | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php |
| CVE-2022-43782 | CRITICAL | 9.8 | 0.9% | Nov 17, 2022 | Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfigur... |
| CVE-2022-43781 | CRITICAL | 9.8 | 98.0% | Nov 17, 2022 | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker ... |
| CVE-2022-42960 | MEDIUM | 5.4 | 0.4% | Nov 17, 2022 | EqualWeb Accessibility Widget 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.10, 3.0.0, 3.0.1, 3.0.2, 4.0.0, and 4.0.1 allows DO... |
| CVE-2022-44006 | CRITICAL | 9.8 | 1.9% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames... |
| CVE-2022-44005 | MEDIUM | 5.3 | 0.6% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the n... |
| CVE-2022-44004 | CRITICAL | 9.8 | 1.2% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthentica... |
| CVE-2022-44003 | CRITICAL | 9.8 | 1.5% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the appli... |
| CVE-2022-44002 | MEDIUM | 6.1 | 0.4% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient output encoding of user-supplied data, the... |
| CVE-2022-44000 | CRITICAL | 9.8 | 0.9% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is pos... |
| CVE-2022-40752 | CRITICAL | 9.8 | 1.8% | Nov 16, 2022 | IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of speci... |
| CVE-2022-44008 | MEDIUM | 6.5 | 0.8% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retri... |
| CVE-2022-44007 | HIGH | 8.8 | 0.8% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is pos... |
| CVE-2022-43999 | CRITICAL | 9.8 | 0.9% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system com... |
| CVE-2022-39319 | MEDIUM | 4.6 | 0.7% | Nov 16, 2022 | FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length val... |
| CVE-2022-39318 | MEDIUM | 5.7 | 1.0% | Nov 16, 2022 | FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation... |
| CVE-2022-39317 | MEDIUM | 4.6 | 0.6% | Nov 16, 2022 | FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check fo... |
| CVE-2022-43135 | CRITICAL | 9.8 | 0.8% | Nov 16, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username pa... |
| CVE-2022-41914 | LOW | 3.7 | 0.5% | Nov 16, 2022 | Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now