2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4011 | CRITICAL | 9.8 | 1.0% | Nov 16, 2022 | A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown proce... |
| CVE-2022-2166 | CRITICAL | 9.8 | 1.0% | Nov 16, 2022 | Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0. |
| CVE-2022-41917 | MEDIUM | 4.3 | 0.5% | Nov 16, 2022 | OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. OpenSearch allows users to specify a loc... |
| CVE-2022-3920 | HIGH | 7.5 | 0.7% | Nov 16, 2022 | HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services... |
| CVE-2022-41918 | MEDIUM | 6.3 | 0.4% | Nov 15, 2022 | OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementatio... |
| CVE-2022-41916 | HIGH | 7.5 | 0.9% | Nov 15, 2022 | Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of ser... |
| CVE-2022-4006 | HIGH | 7.5 | 0.8% | Nov 15, 2022 | A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function... |
| CVE-2022-30769 | MEDIUM | 4.6 | 0.5% | Nov 15, 2022 | Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in u... |
| CVE-2022-30768 | MEDIUM | 5.4 | 0.6% | Nov 15, 2022 | A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code vi... |
| CVE-2022-29279 | HIGH | 8.2 | 0.2% | Nov 15, 2022 | Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted ... |
| CVE-2022-29278 | HIGH | 8.2 | 0.2% | Nov 15, 2022 | Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer ... |
| CVE-2022-29277 | HIGH | 8.8 | 0.2% | Nov 15, 2022 | Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of ... |
| CVE-2022-29276 | HIGH | 8.2 | 0.2% | Nov 15, 2022 | SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrust... |
| CVE-2022-43279 | HIGH | 7.2 | 0.9% | Nov 15, 2022 | LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/th... |
| CVE-2022-43265 | CRITICAL | 9.8 | 0.9% | Nov 15, 2022 | An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows at... |
| CVE-2022-42785 | CRITICAL | 9.8 | 1.0% | Nov 15, 2022 | Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, ... |
| CVE-2022-40753 | MEDIUM | 5.4 | 0.4% | Nov 15, 2022 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2022-3377 | HIGH | 7.8 | 0.2% | Nov 15, 2022 | Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a ... |
| CVE-2022-38385 | HIGH | 8.1 | 0.5% | Nov 15, 2022 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitiv... |
| CVE-2022-38201 | MEDIUM | 6.1 | 0.5% | Nov 15, 2022 | An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.... |
| CVE-2022-30772 | HIGH | 8.2 | 0.2% | Nov 15, 2022 | Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memor... |
| CVE-2022-30771 | HIGH | 8.2 | 0.2% | Nov 15, 2022 | Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization ... |
| CVE-2022-30283 | HIGH | 7.5 | 0.1% | Nov 15, 2022 | In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in pro... |
| CVE-2022-29275 | HIGH | 8.2 | 0.2% | Nov 15, 2022 | In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM ... |
| CVE-2022-24942 | CRITICAL | 9.8 | 1.9% | Nov 15, 2022 | Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTT... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now