2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-33985 | HIGH | 7 | 0.1% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the NvmExpressDxe software SMI handler could cause SMRAM c... |
| CVE-2022-33984 | HIGH | 7 | 0.2% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the SdMmcDevice software SMI handler could cause SMRAM cor... |
| CVE-2022-33983 | HIGH | 7 | 0.2% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRA... |
| CVE-2022-33909 | HIGH | 7 | 0.1% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM cor... |
| CVE-2022-33908 | HIGH | 7 | 0.1% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM co... |
| CVE-2022-33906 | MEDIUM | 6.4 | 0.2% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMR... |
| CVE-2022-33905 | HIGH | 7 | 0.1% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the AhciBusDxe software SMI handler could cause SMRAM corr... |
| CVE-2022-32267 | MEDIUM | 6.4 | 0.1% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM c... |
| CVE-2022-31243 | MEDIUM | 6.4 | 0.2% | Nov 15, 2022 | Update description and links DMA transactions which are targeted at input buffers used for the software SMI handler used... |
| CVE-2022-30774 | MEDIUM | 6.4 | 0.2% | Nov 15, 2022 | DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been... |
| CVE-2022-43695 | MEDIUM | 4.8 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2022-43691 | MEDIUM | 5.3 | 0.4% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive ... |
| CVE-2022-43690 | MEDIUM | 6.3 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_... |
| CVE-2022-43689 | MEDIUM | 5.3 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leadi... |
| CVE-2022-43688 | MEDIUM | 4.8 | 0.5% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2022-43687 | MEDIUM | 5.4 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 does not issue a new session ID upon successf... |
| CVE-2022-43030 | HIGH | 7.2 | 1.9% | Nov 14, 2022 | Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a con... |
| CVE-2022-40903 | MEDIUM | 6.5 | 0.3% | Nov 14, 2022 | Aiphone GT-DMB-N 3-in-1 Video Entrance Station with NFC Reader 1.0.3 does not mitigate against repeated failed access at... |
| CVE-2022-40735 | HIGH | 7.5 | 2.3% | Nov 14, 2022 | The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessa... |
| CVE-2022-34325 | HIGH | 7.8 | 0.1% | Nov 14, 2022 | DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could c... |
| CVE-2022-33982 | MEDIUM | 6.4 | 0.2% | Nov 14, 2022 | DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a TOCTOU attack on th... |
| CVE-2022-33907 | MEDIUM | 6.4 | 0.2% | Nov 14, 2022 | DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver coul... |
| CVE-2022-43968 | MEDIUM | 6.1 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the dashboa... |
| CVE-2022-43967 | MEDIUM | 6.1 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the multili... |
| CVE-2022-43686 | MEDIUM | 6.5 | 1.0% | Nov 14, 2022 | In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can b... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now