2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41680 | MEDIUM | 6.5 | 0.3% | Oct 31, 2022 | Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vuln... |
| CVE-2022-41679 | MEDIUM | 6.1 | 0.5% | Oct 31, 2022 | Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote att... |
| CVE-2022-41657 | CRITICAL | 9.8 | 20.9% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized... |
| CVE-2022-41644 | HIGH | 8.8 | 0.7% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that chan... |
| CVE-2022-41629 | CRITICAL | 9.1 | 0.6% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprun... |
| CVE-2022-40202 | CRITICAL | 9.8 | 1.2% | Oct 31, 2022 | The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper au... |
| CVE-2022-3499 | MEDIUM | 6.5 | 0.8% | Oct 31, 2022 | An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a sce... |
| CVE-2022-38142 | CRITICAL | 9.8 | 18.2% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through... |
| CVE-2022-31692 | CRITICAL | 9.8 | 3.4% | Oct 31, 2022 | Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass v... |
| CVE-2022-31690 | HIGH | 8.1 | 1.0% | Oct 31, 2022 | Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptibl... |
| CVE-2022-28763 | CRITICAL | 9.6 | 1.1% | Oct 31, 2022 | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL... |
| CVE-2022-27583 | CRITICAL | 9.1 | 0.6% | Oct 31, 2022 | A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2... |
| CVE-2022-44081 | MEDIUM | 5.5 | 0.3% | Oct 31, 2022 | Lodepng v20220717 was discovered to contain a segmentation fault via the function pngdetail. |
| CVE-2022-44079 | MEDIUM | 5.5 | 0.3% | Oct 31, 2022 | pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component __san... |
| CVE-2022-43152 | MEDIUM | 5.5 | 0.3% | Oct 31, 2022 | tsMuxer v2.6.16 was discovered to contain a heap overflow via the function BitStreamWriter::flushBits() at /tsMuxer/bitS... |
| CVE-2022-43151 | MEDIUM | 5.5 | 0.3% | Oct 31, 2022 | timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-quer... |
| CVE-2022-43148 | MEDIUM | 5.5 | 0.3% | Oct 31, 2022 | rtf2html v0.2.0 was discovered to contain a heap overflow in the component /rtf2html/./rtf_tools.h. |
| CVE-2022-39294 | HIGH | 7.5 | 0.7% | Oct 31, 2022 | conduit-hyper integrates a conduit application with the hyper server. Prior to version 0.4.2, `conduit-hyper` did not ch... |
| CVE-2022-2741 | HIGH | 7.5 | 0.6% | Oct 31, 2022 | The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vuln... |
| CVE-2022-40471 | CRITICAL | 9.8 | 19.4% | Oct 31, 2022 | Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p... |
| CVE-2022-3774 | CRITICAL | 9.1 | 1.1% | Oct 31, 2022 | A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue i... |
| CVE-2022-3773 | — | — | — | Oct 31, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3441 | MEDIUM | 4.8 | 0.5% | Oct 31, 2022 | The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2022-3440 | MEDIUM | 6.1 | 0.5% | Oct 31, 2022 | The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attr... |
| CVE-2022-3420 | MEDIUM | 4.8 | 0.5% | Oct 31, 2022 | The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, w... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now