2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43449 | MEDIUM | 5.5 | 0.2% | Nov 3, 2022 | OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can ... |
| CVE-2022-43063 | HIGH | 7.2 | 0.7% | Nov 3, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-43062 | HIGH | 7.2 | 0.7% | Nov 3, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-43061 | HIGH | 7.2 | 0.9% | Nov 3, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the co... |
| CVE-2022-42749 | MEDIUM | 6.1 | 1.1% | Nov 3, 2022 | CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitra... |
| CVE-2022-42748 | MEDIUM | 6.1 | 1.1% | Nov 3, 2022 | CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie o... |
| CVE-2022-42747 | MEDIUM | 6.1 | 1.1% | Nov 3, 2022 | CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbit... |
| CVE-2022-42746 | MEDIUM | 6.1 | 1.1% | Nov 3, 2022 | CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of ar... |
| CVE-2022-42745 | HIGH | 7.5 | 0.8% | Nov 3, 2022 | CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because th... |
| CVE-2022-42744 | CRITICAL | 9.8 | 1.2% | Nov 3, 2022 | CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is pos... |
| CVE-2022-42743 | MEDIUM | 5.3 | 0.6% | Nov 3, 2022 | deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible b... |
| CVE-2022-42442 | LOW | 3.3 | 0.2% | Nov 3, 2022 | IBM Robotic Process Automation for Cloud Pak 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to exposure of th... |
| CVE-2022-41714 | MEDIUM | 5.3 | 0.6% | Nov 3, 2022 | fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible... |
| CVE-2022-41713 | MEDIUM | 5.3 | 0.6% | Nov 3, 2022 | deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible ... |
| CVE-2022-41710 | MEDIUM | 5.5 | 0.4% | Nov 3, 2022 | Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attemp... |
| CVE-2022-40747 | CRITICAL | 9.1 | 0.9% | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing X... |
| CVE-2022-40276 | MEDIUM | 5.5 | 0.4% | Nov 3, 2022 | Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to... |
| CVE-2022-40235 | MEDIUM | 6.5 | 0.6% | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run j... |
| CVE-2022-40230 | MEDIUM | 6.5 | 0.4% | Nov 3, 2022 | "IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an aut... |
| CVE-2022-40131 | MEDIUM | 4.3 | 0.2% | Nov 3, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Page View Count plugin <= 2.5.5 on WordPress allows an... |
| CVE-2022-38712 | MEDIUM | 5.9 | 0.5% | Nov 3, 2022 | "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduc... |
| CVE-2022-38710 | MEDIUM | 5.3 | 0.3% | Nov 3, 2022 | IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere info... |
| CVE-2022-36428 | MEDIUM | 4.8 | 0.4% | Nov 3, 2022 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress. |
| CVE-2022-36404 | MEDIUM | 5.4 | 0.2% | Nov 3, 2022 | Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugi... |
| CVE-2022-35717 | HIGH | 7.8 | 0.6% | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on th... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now