2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3574 | CRITICAL | 9.8 | 1.3% | Nov 14, 2022 | The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which co... |
| CVE-2022-3477 | CRITICAL | 9.8 | 3.5% | Nov 14, 2022 | The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordP... |
| CVE-2022-45378 | CRITICAL | 9.8 | 2.3% | Nov 14, 2022 | In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an atta... |
| CVE-2022-3973 | CRITICAL | 9.8 | 0.6% | Nov 13, 2022 | A vulnerability classified as critical has been found in Pingkon HMS-PHP. Affected is an unknown function of the file /a... |
| CVE-2022-3972 | CRITICAL | 9.8 | 0.6% | Nov 13, 2022 | A vulnerability was found in Pingkon HMS-PHP. It has been rated as critical. This issue affects some unknown processing ... |
| CVE-2022-38652 | CRITICAL | 9.9 | 0.8% | Nov 12, 2022 | A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerabilit... |
| CVE-2022-38651 | CRITICAL | 9.8 | 0.8% | Nov 12, 2022 | A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a m... |
| CVE-2022-38650 | CRITICAL | 10 | 0.8% | Nov 12, 2022 | A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of t... |
| CVE-2022-43672 | CRITICAL | 9.8 | 67.1% | Nov 12, 2022 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL I... |
| CVE-2022-43671 | CRITICAL | 9.8 | 74.8% | Nov 12, 2022 | Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL I... |
| CVE-2022-45182 | CRITICAL | 9.8 | 0.9% | Nov 11, 2022 | Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter. |
| CVE-2022-34331 | CRITICAL | 9.8 | 0.5% | Nov 11, 2022 | After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly con... |
| CVE-2022-3956 | CRITICAL | 9.8 | 0.7% | Nov 11, 2022 | A vulnerability classified as critical has been found in tsruban HHIMS 2.1. Affected is an unknown function of the compo... |
| CVE-2022-3955 | CRITICAL | 9.8 | 0.7% | Nov 11, 2022 | A vulnerability was found in tholum crm42. It has been rated as critical. This issue affects some unknown processing of ... |
| CVE-2022-29486 | CRITICAL | 9.8 | 0.5% | Nov 11, 2022 | Improper buffer restrictions in the Hyperscan library maintained by Intel(R) all versions downloaded before 04/29/2022 m... |
| CVE-2022-26845 | CRITICAL | 9.8 | 0.6% | Nov 11, 2022 | Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0... |
| CVE-2022-26513 | CRITICAL | 9.6 | 0.3% | Nov 11, 2022 | Out-of-bounds write in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow an unauth... |
| CVE-2022-3948 | CRITICAL | 9.8 | 0.7% | Nov 11, 2022 | A vulnerability classified as critical was found in eolinker goku_lite. This vulnerability affects unknown code of the f... |
| CVE-2022-3947 | CRITICAL | 9.8 | 0.7% | Nov 11, 2022 | A vulnerability classified as critical has been found in eolinker goku_lite. This affects an unknown part of the file /b... |
| CVE-2022-3940 | CRITICAL | 9.8 | 0.6% | Nov 11, 2022 | A vulnerability, which was classified as problematic, was found in lanyulei ferry. This affects an unknown part of the f... |
| CVE-2022-3939 | CRITICAL | 9.8 | 0.6% | Nov 11, 2022 | A vulnerability, which was classified as critical, has been found in lanyulei ferry. Affected by this issue is some unkn... |
| CVE-2022-41892 | CRITICAL | 9.8 | 0.5% | Nov 11, 2022 | Arches is a web platform for creating, managing, & visualizing geospatial data. Versions prior to 6.1.2, 6.2.1, and 7.1.... |
| CVE-2022-36938 | CRITICAL | 9.8 | 1.2% | Nov 11, 2022 | DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loadin... |
| CVE-2022-41878 | CRITICAL | 9.8 | 0.9% | Nov 10, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio... |
| CVE-2022-40981 | CRITICAL | 10 | 0.5% | Nov 10, 2022 | All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attac... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now