2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4015 | CRITICAL | 9.8 | 0.5% | Nov 16, 2022 | A vulnerability, which was classified as critical, was found in Sports Club Management System 119. This affects an unkno... |
| CVE-2022-4012 | CRITICAL | 9.8 | 0.5% | Nov 16, 2022 | A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of ... |
| CVE-2022-4011 | CRITICAL | 9.8 | 1.0% | Nov 16, 2022 | A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown proce... |
| CVE-2022-2166 | CRITICAL | 9.8 | 1.0% | Nov 16, 2022 | Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0. |
| CVE-2022-43265 | CRITICAL | 9.8 | 0.9% | Nov 15, 2022 | An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows at... |
| CVE-2022-42785 | CRITICAL | 9.8 | 1.0% | Nov 15, 2022 | Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, ... |
| CVE-2022-24942 | CRITICAL | 9.8 | 1.9% | Nov 15, 2022 | Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTT... |
| CVE-2022-45400 | CRITICAL | 9.8 | 1.1% | Nov 15, 2022 | Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2022-45397 | CRITICAL | 9.8 | 1.0% | Nov 15, 2022 | Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML exter... |
| CVE-2022-45396 | CRITICAL | 9.8 | 1.0% | Nov 15, 2022 | Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) atta... |
| CVE-2022-45395 | CRITICAL | 9.8 | 1.1% | Nov 15, 2022 | Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2022-3998 | CRITICAL | 9.8 | 0.5% | Nov 15, 2022 | A vulnerability, which was classified as critical, was found in MonikaBrzica scm. This affects an unknown part of the fi... |
| CVE-2022-33234 | CRITICAL | 9.8 | 0.3% | Nov 15, 2022 | Memory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivit... |
| CVE-2022-25727 | CRITICAL | 9.8 | 0.4% | Nov 15, 2022 | Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon... |
| CVE-2022-25674 | CRITICAL | 9.8 | 0.3% | Nov 15, 2022 | Cryptographic issues in WLAN during the group key handshake of the WPA/WPA2 protocol in Snapdragon Consumer IOT, Snapdra... |
| CVE-2022-42058 | CRITICAL | 9.8 | 1.2% | Nov 15, 2022 | Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage... |
| CVE-2022-42122 | CRITICAL | 9.8 | 0.8% | Nov 15, 2022 | A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through... |
| CVE-2022-42120 | CRITICAL | 9.8 | 0.8% | Nov 15, 2022 | A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 befor... |
| CVE-2022-42984 | CRITICAL | 9.8 | 0.7% | Nov 15, 2022 | WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter ... |
| CVE-2022-43294 | CRITICAL | 9.8 | 0.9% | Nov 14, 2022 | Tasmota before commit 066878da4d4762a9b6cb169fdf353e804d735cfd was discovered to contain a stack overflow via the Client... |
| CVE-2022-3362 | CRITICAL | 9.8 | 0.9% | Nov 14, 2022 | Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0. |
| CVE-2022-37109 | CRITICAL | 9.8 | 49.2% | Nov 14, 2022 | patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access... |
| CVE-2022-3993 | CRITICAL | 9.8 | 1.1% | Nov 14, 2022 | Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3. |
| CVE-2022-24937 | CRITICAL | 9.8 | 0.7% | Nov 14, 2022 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows ... |
| CVE-2022-45136 | CRITICAL | 9.8 | 1.5% | Nov 14, 2022 | Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now