2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40739 | MEDIUM | 5.4 | 0.4% | Oct 31, 2022 | Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user priv... |
| CVE-2022-39027 | MEDIUM | 5.4 | 0.4% | Oct 31, 2022 | U-Office Force Forum function has insufficient filtering for special characters. A remote attacker with general user pri... |
| CVE-2022-39026 | MEDIUM | 5.4 | 0.4% | Oct 31, 2022 | U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote at... |
| CVE-2022-39025 | MEDIUM | 6.1 | 0.5% | Oct 31, 2022 | U-Office Force PrintMessage function has insufficient filtering for special characters. An unauthenticated remote attack... |
| CVE-2022-39024 | MEDIUM | 6.1 | 0.5% | Oct 31, 2022 | U-Office Force Bulletin function has insufficient filtering for special characters. An unauthenticated remote attacker c... |
| CVE-2022-39023 | MEDIUM | 6.5 | 0.9% | Oct 31, 2022 | U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can e... |
| CVE-2022-39022 | MEDIUM | 6.5 | 0.9% | Oct 31, 2022 | U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can e... |
| CVE-2022-39021 | MEDIUM | 6.1 | 0.5% | Oct 31, 2022 | U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vu... |
| CVE-2022-40617 | HIGH | 7.5 | 1.6% | Oct 31, 2022 | strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a craft... |
| CVE-2022-44034 | MEDIUM | 6.4 | 0.3% | Oct 30, 2022 | An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resu... |
| CVE-2022-44033 | MEDIUM | 6.4 | 0.3% | Oct 30, 2022 | An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4040_cs.c has a race condition and resu... |
| CVE-2022-44032 | MEDIUM | 6.4 | 0.3% | Oct 30, 2022 | An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4000_cs.c has a race condition and resu... |
| CVE-2022-44023 | MEDIUM | 5.3 | 0.7% | Oct 30, 2022 | PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response message... |
| CVE-2022-44022 | MEDIUM | 5.3 | 0.7% | Oct 30, 2022 | PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings fo... |
| CVE-2022-44020 | MEDIUM | 5.5 | 0.2% | Oct 30, 2022 | An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device c... |
| CVE-2022-44019 | HIGH | 8.8 | 2.0% | Oct 30, 2022 | In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host... |
| CVE-2022-42915 | HIGH | 8.1 | 2.9% | Oct 29, 2022 | curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it set... |
| CVE-2022-41974 | HIGH | 7.8 | 0.6% | Oct 29, 2022 | multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conj... |
| CVE-2022-41973 | HIGH | 7.8 | 0.7% | Oct 29, 2022 | multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction w... |
| CVE-2022-3757 | — | — | — | Oct 29, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3756 | — | — | — | Oct 29, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3755 | — | — | — | Oct 29, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3754 | CRITICAL | 9.8 | 1.1% | Oct 29, 2022 | Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8. |
| CVE-2022-42916 | HIGH | 7.5 | 1.6% | Oct 29, 2022 | In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl... |
| CVE-2022-2826 | CRITICAL | 9.8 | 0.8% | Oct 28, 2022 | An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting fr... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now