2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20772 | MEDIUM | 5.3 | 0.5% | Nov 4, 2022 | A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenti... |
| CVE-2022-27893 | MEDIUM | 4.2 | 0.2% | Nov 4, 2022 | The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that c... |
| CVE-2022-41671 | HIGH | 7.8 | 0.3% | Nov 4, 2022 | A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that al... |
| CVE-2022-41670 | HIGH | 7.8 | 0.2% | Nov 4, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGI... |
| CVE-2022-41669 | HIGH | 7.8 | 0.1% | Nov 4, 2022 | A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows... |
| CVE-2022-3721 | MEDIUM | 4.6 | 0.8% | Nov 4, 2022 | Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39. |
| CVE-2022-41668 | HIGH | 7.8 | 0.2% | Nov 4, 2022 | A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load ... |
| CVE-2022-41667 | HIGH | 7.8 | 0.2% | Nov 4, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allow... |
| CVE-2022-3340 | HIGH | 7.2 | 0.5% | Nov 4, 2022 | XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administra... |
| CVE-2022-3023 | CRITICAL | 9.8 | 0.6% | Nov 4, 2022 | Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3. |
| CVE-2022-38582 | MEDIUM | 6.5 | 0.6% | Nov 4, 2022 | Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arb... |
| CVE-2022-33684 | HIGH | 8.1 | 0.7% | Nov 4, 2022 | The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Crede... |
| CVE-2022-44724 | MEDIUM | 5.4 | 0.7% | Nov 4, 2022 | The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers... |
| CVE-2022-41666 | HIGH | 7.8 | 0.1% | Nov 4, 2022 | A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user... |
| CVE-2022-43571 | HIGH | 8.8 | 14.3% | Nov 3, 2022 | In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through t... |
| CVE-2022-43561 | MEDIUM | 4.8 | 0.6% | Nov 3, 2022 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store... |
| CVE-2022-38168 | CRITICAL | 9.1 | 1.1% | Nov 3, 2022 | Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote un... |
| CVE-2022-44628 | MEDIUM | 4.8 | 0.4% | Nov 3, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JumpDEMAND Inc. 4ECPS Web Forms plugin <= 0.2.17 on Wo... |
| CVE-2022-44627 | MEDIUM | 5.4 | 0.2% | Nov 3, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 1.8.12 on WordPress allows attackers ... |
| CVE-2022-43574 | HIGH | 7.5 | 0.5% | Nov 3, 2022 | "IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignm... |
| CVE-2022-43495 | HIGH | 7.5 | 0.6% | Nov 3, 2022 | OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a netwo... |
| CVE-2022-43451 | MEDIUM | 6.5 | 0.2% | Nov 3, 2022 | OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. L... |
| CVE-2022-43449 | MEDIUM | 5.5 | 0.2% | Nov 3, 2022 | OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can ... |
| CVE-2022-43063 | HIGH | 7.2 | 0.7% | Nov 3, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-43062 | HIGH | 7.2 | 0.7% | Nov 3, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now