2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41878 | CRITICAL | 9.8 | 0.9% | Nov 10, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio... |
| CVE-2022-42460 | MEDIUM | 5.4 | 0.4% | Nov 10, 2022 | Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on W... |
| CVE-2022-41607 | HIGH | 7.5 | 1.0% | Nov 10, 2022 | All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vu... |
| CVE-2022-40981 | CRITICAL | 10 | 0.5% | Nov 10, 2022 | All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attac... |
| CVE-2022-40225 | HIGH | 7.5 | 0.6% | Nov 10, 2022 | A vulnerability has been identified in SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6... |
| CVE-2022-3703 | CRITICAL | 10 | 0.3% | Nov 10, 2022 | All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting maliciou... |
| CVE-2022-28748 | — | — | — | Nov 10, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2964. Reason: This candidate is a reservation du... |
| CVE-2022-43679 | MEDIUM | 5.3 | 0.3% | Nov 10, 2022 | The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config us... |
| CVE-2022-41879 | CRITICAL | 9.8 | 0.8% | Nov 10, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio... |
| CVE-2022-41876 | MEDIUM | 5.3 | 1.3% | Nov 10, 2022 | ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and ... |
| CVE-2022-41874 | MEDIUM | 4.7 | 0.4% | Nov 10, 2022 | Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri ... |
| CVE-2022-35740 | MEDIUM | 6.1 | 1.2% | Nov 10, 2022 | dotCMS before 22.06 allows remote attackers to bypass intended access control and obtain sensitive information by using ... |
| CVE-2022-26088 | MEDIUM | 5.4 | 1.0% | Nov 10, 2022 | An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to ... |
| CVE-2022-43074 | CRITICAL | 9.8 | 0.9% | Nov 10, 2022 | AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.p... |
| CVE-2022-41719 | HIGH | 7.5 | 1.0% | Nov 10, 2022 | Unmarshal can panic on some inputs, possibly allowing for denial of service attacks. |
| CVE-2022-39394 | CRITICAL | 9.8 | 0.3% | Nov 10, 2022 | Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's C API implementat... |
| CVE-2022-39393 | HIGH | 8.6 | 0.7% | Nov 10, 2022 | Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implem... |
| CVE-2022-39392 | HIGH | 7.4 | 0.6% | Nov 10, 2022 | Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's implementation of... |
| CVE-2022-39388 | LOW | 3.5 | 0.5% | Nov 10, 2022 | Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3... |
| CVE-2022-39395 | CRITICAL | 9.9 | 1.1% | Nov 10, 2022 | Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server an... |
| CVE-2022-36022 | MEDIUM | 5.3 | 0.4% | Nov 10, 2022 | Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM. Packages org.deeplearn... |
| CVE-2022-44727 | CRITICAL | 9.1 | 2.4% | Nov 10, 2022 | The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcooki... |
| CVE-2022-45063 | CRITICAL | 9.8 | 4.9% | Nov 10, 2022 | xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead... |
| CVE-2022-34666 | MEDIUM | 5.5 | 0.2% | Nov 10, 2022 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user wi... |
| CVE-2022-44089 | CRITICAL | 9.8 | 1.6% | Nov 10, 2022 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now