2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3966 | HIGH | 7.5 | 0.7% | Nov 13, 2022 | A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affe... |
| CVE-2022-3965 | HIGH | 8.1 | 0.9% | Nov 13, 2022 | A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream... |
| CVE-2022-3964 | HIGH | 8.1 | 3.5% | Nov 13, 2022 | A vulnerability classified as problematic has been found in ffmpeg. This affects an unknown part of the file libavcodec/... |
| CVE-2022-3963 | MEDIUM | 5.4 | 0.4% | Nov 12, 2022 | A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the fi... |
| CVE-2022-45196 | HIGH | 7.5 | 0.8% | Nov 12, 2022 | Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted cha... |
| CVE-2022-45195 | MEDIUM | 5.3 | 0.6% | Nov 12, 2022 | SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, w... |
| CVE-2022-45188 | HIGH | 7.8 | 0.6% | Nov 12, 2022 | Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl fi... |
| CVE-2022-38652 | CRITICAL | 9.9 | 0.8% | Nov 12, 2022 | A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerabilit... |
| CVE-2022-38651 | CRITICAL | 9.8 | 0.8% | Nov 12, 2022 | A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a m... |
| CVE-2022-38650 | CRITICAL | 10 | 0.8% | Nov 12, 2022 | A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of t... |
| CVE-2022-43672 | CRITICAL | 9.8 | 67.1% | Nov 12, 2022 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL I... |
| CVE-2022-43671 | CRITICAL | 9.8 | 74.8% | Nov 12, 2022 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL I... |
| CVE-2022-41339 | HIGH | 7.8 | 0.5% | Nov 12, 2022 | In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege esca... |
| CVE-2022-40773 | HIGH | 8.8 | 4.5% | Nov 12, 2022 | Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege esca... |
| CVE-2022-45194 | MEDIUM | 4.7 | 0.4% | Nov 12, 2022 | CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure. |
| CVE-2022-45193 | HIGH | 8.8 | 0.5% | Nov 12, 2022 | CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privil... |
| CVE-2022-41905 | MEDIUM | 6.1 | 0.3% | Nov 11, 2022 | WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory brows... |
| CVE-2022-45182 | CRITICAL | 9.8 | 0.9% | Nov 11, 2022 | Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter. |
| CVE-2022-41906 | HIGH | 8.7 | 0.7% | Nov 11, 2022 | OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via E... |
| CVE-2022-41904 | MEDIUM | 6.5 | 0.4% | Nov 11, 2022 | Element iOS is an iOS Matrix client provided by Element. It is based on MatrixSDK. Prior to version 1.9.7, events encryp... |
| CVE-2022-41882 | HIGH | 7.8 | 0.5% | Nov 11, 2022 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. In version 3.6.0, ... |
| CVE-2022-40750 | MEDIUM | 5.4 | 0.4% | Nov 11, 2022 | IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to ... |
| CVE-2022-38387 | HIGH | 8.8 | 0.9% | Nov 11, 2022 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbit... |
| CVE-2022-36776 | MEDIUM | 5.4 | 0.4% | Nov 11, 2022 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allo... |
| CVE-2022-31772 | MEDIUM | 6.5 | 0.7% | Nov 11, 2022 | IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a d... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now