2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44646 | MEDIUM | 5.3 | 0.4% | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings |
| CVE-2022-44624 | HIGH | 7.5 | 0.5% | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained sp... |
| CVE-2022-44623 | HIGH | 7.5 | 0.5% | Nov 3, 2022 | In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner setting... |
| CVE-2022-44622 | MEDIUM | 5.3 | 0.4% | Nov 3, 2022 | In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive |
| CVE-2022-43109 | CRITICAL | 9.8 | 3.7% | Nov 3, 2022 | D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettin... |
| CVE-2022-43108 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewal... |
| CVE-2022-43107 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagem... |
| CVE-2022-43106 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWi... |
| CVE-2022-43105 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGus... |
| CVE-2022-43104 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWire... |
| CVE-2022-43103 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand funct... |
| CVE-2022-43102 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime f... |
| CVE-2022-43101 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName... |
| CVE-2022-39382 | CRITICAL | 9.8 | 1.5% | Nov 3, 2022 | Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/core@3.0.0 || 3.0.1` users that use `... |
| CVE-2022-39276 | MEDIUM | 5.3 | 0.6% | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr... |
| CVE-2022-39262 | MEDIUM | 4.8 | 0.6% | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package, GLPI a... |
| CVE-2022-39234 | HIGH | 8.8 | 0.4% | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr... |
| CVE-2022-41435 | MEDIUM | 5.4 | 0.5% | Nov 3, 2022 | OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerabilit... |
| CVE-2022-32287 | HIGH | 7.5 | 1.6% | Nov 3, 2022 | A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows ... |
| CVE-2022-44638 | HIGH | 8.8 | 1.4% | Nov 3, 2022 | In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edge... |
| CVE-2022-44586 | MEDIUM | 4.8 | 0.4% | Nov 2, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) in Ayoub Media AM-HiLi plugin <= 1.0 on WordPress. |
| CVE-2022-44576 | MEDIUM | 4.8 | 0.4% | Nov 2, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in AgentEasy Properties plugin <= 1.0.4 on WordPress. |
| CVE-2022-24945 | — | — | — | Nov 2, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3181 | HIGH | 7.5 | 0.7% | Nov 2, 2022 | An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malform... |
| CVE-2022-43068 | HIGH | 7.2 | 0.7% | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now