2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40293 | CRITICAL | 9.8 | 0.6% | Oct 31, 2022 | The application was vulnerable to a session fixation that could be used hijack accounts. |
| CVE-2022-40292 | MEDIUM | 5.3 | 0.5% | Oct 31, 2022 | The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve info... |
| CVE-2022-40291 | HIGH | 8.8 | 0.3% | Oct 31, 2022 | The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into ... |
| CVE-2022-40290 | MEDIUM | 6.1 | 0.4% | Oct 31, 2022 | The application was vulnerable to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the barcode ... |
| CVE-2022-40289 | CRITICAL | 9 | 0.6% | Oct 31, 2022 | The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functio... |
| CVE-2022-40288 | CRITICAL | 9 | 0.6% | Oct 31, 2022 | The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, w... |
| CVE-2022-40287 | CRITICAL | 9 | 0.6% | Oct 31, 2022 | The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messa... |
| CVE-2022-40190 | CRITICAL | 9.6 | 0.7% | Oct 31, 2022 | SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web applicati... |
| CVE-2022-3785 | HIGH | 7.8 | 0.6% | Oct 31, 2022 | A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the fun... |
| CVE-2022-3784 | HIGH | 7.8 | 0.6% | Oct 31, 2022 | A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the func... |
| CVE-2022-3783 | MEDIUM | 6.1 | 0.6% | Oct 31, 2022 | A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unkn... |
| CVE-2022-3059 | HIGH | 7.5 | 0.5% | Oct 31, 2022 | The application was vulnerable to multiple instances of SQL injection (authenticated and unauthenticated) through a vul... |
| CVE-2022-39020 | MEDIUM | 6.1 | 0.4% | Oct 31, 2022 | Multiple instances of XSS (stored and reflected) was found in the application. For example, features such as student as... |
| CVE-2022-39019 | HIGH | 7.5 | 0.4% | Oct 31, 2022 | Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to u... |
| CVE-2022-39018 | HIGH | 7.5 | 0.4% | Oct 31, 2022 | Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access r... |
| CVE-2022-39017 | MEDIUM | 5.4 | 0.4% | Oct 31, 2022 | Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows auth... |
| CVE-2022-39016 | HIGH | 8.8 | 0.5% | Oct 31, 2022 | Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an accoun... |
| CVE-2022-42925 | HIGH | 8.8 | 0.9% | Oct 31, 2022 | There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the rol... |
| CVE-2022-42924 | MEDIUM | 6.5 | 0.4% | Oct 31, 2022 | Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vuln... |
| CVE-2022-42923 | HIGH | 8.8 | 0.6% | Oct 31, 2022 | Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vuln... |
| CVE-2022-41779 | CRITICAL | 9.8 | 1.1% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper veri... |
| CVE-2022-41776 | HIGH | 7.5 | 0.5% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the Writ... |
| CVE-2022-41772 | CRITICAL | 9.8 | 24.9% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters u... |
| CVE-2022-41688 | HIGH | 7.5 | 0.6% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that c... |
| CVE-2022-41681 | HIGH | 8.8 | 0.9% | Oct 31, 2022 | There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the rol... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now