2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45061 | HIGH | 7.5 | 2.5% | Nov 9, 2022 | An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing s... |
| CVE-2022-40797 | CRITICAL | 9.8 | 2.6% | Nov 9, 2022 | Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.... |
| CVE-2022-45060 | HIGH | 7.5 | 0.9% | Nov 9, 2022 | An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x bef... |
| CVE-2022-45059 | HIGH | 7.5 | 1.2% | Nov 9, 2022 | An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be perf... |
| CVE-2022-3890 | CRITICAL | 9.6 | 0.7% | Nov 9, 2022 | Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had c... |
| CVE-2022-3889 | HIGH | 8.8 | 0.6% | Nov 9, 2022 | Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2022-3888 | HIGH | 8.8 | 0.6% | Nov 9, 2022 | Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit he... |
| CVE-2022-3887 | HIGH | 8.8 | 0.6% | Nov 9, 2022 | Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit ... |
| CVE-2022-3886 | HIGH | 8.8 | 0.6% | Nov 9, 2022 | Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially e... |
| CVE-2022-3885 | HIGH | 8.8 | 0.7% | Nov 9, 2022 | Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2022-39390 | — | — | — | Nov 9, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-36534. Reason: This candidate is a reservation d... |
| CVE-2022-43144 | MEDIUM | 5.4 | 0.9% | Nov 8, 2022 | A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web s... |
| CVE-2022-39328 | HIGH | 8.1 | 0.9% | Nov 8, 2022 | Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 co... |
| CVE-2022-30515 | MEDIUM | 5.3 | 0.7% | Nov 8, 2022 | ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them ... |
| CVE-2022-41260 | MEDIUM | 6.1 | 0.4% | Nov 8, 2022 | SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauth... |
| CVE-2022-41259 | MEDIUM | 6.5 | 0.7% | Nov 8, 2022 | SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywh... |
| CVE-2022-41258 | MEDIUM | 6.5 | 0.4% | Nov 8, 2022 | Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to in... |
| CVE-2022-41215 | MEDIUM | 4.7 | 0.4% | Nov 8, 2022 | SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due... |
| CVE-2022-41214 | HIGH | 8.7 | 0.7% | Nov 8, 2022 | Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with hi... |
| CVE-2022-41212 | MEDIUM | 4.9 | 0.8% | Nov 8, 2022 | Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with hi... |
| CVE-2022-41211 | HIGH | 7.8 | 0.3% | Nov 8, 2022 | Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D ... |
| CVE-2022-41208 | MEDIUM | 5.4 | 0.4% | Nov 8, 2022 | Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with ... |
| CVE-2022-41207 | MEDIUM | 6.1 | 0.4% | Nov 8, 2022 | SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting ... |
| CVE-2022-41205 | MEDIUM | 6.1 | 0.2% | Nov 8, 2022 | SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attack... |
| CVE-2022-41203 | HIGH | 8.8 | 0.9% | Nov 8, 2022 | In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated atta... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now