2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43286 | CRITICAL | 9.8 | 0.9% | Oct 28, 2022 | Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_j... |
| CVE-2022-43285 | HIGH | 7.5 | 0.7% | Oct 28, 2022 | Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disput... |
| CVE-2022-43284 | HIGH | 7.5 | 0.8% | Oct 28, 2022 | Nginx NJS v0.7.2 to v0.7.4 was discovered to contain a segmentation violation via njs_scope_valid_value at njs_scope.h. ... |
| CVE-2022-43283 | MEDIUM | 5.5 | 0.3% | Oct 28, 2022 | wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write. |
| CVE-2022-43282 | HIGH | 7.1 | 0.3% | Oct 28, 2022 | wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetRetur... |
| CVE-2022-43281 | HIGH | 7.8 | 0.3% | Oct 28, 2022 | wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<w... |
| CVE-2022-43280 | HIGH | 7.1 | 0.3% | Oct 28, 2022 | wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDro... |
| CVE-2022-37621 | CRITICAL | 9.8 | 1.0% | Oct 28, 2022 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th... |
| CVE-2022-3708 | HIGH | 8.1 | 0.7% | Oct 28, 2022 | The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.... |
| CVE-2022-3402 | MEDIUM | 6.1 | 0.6% | Oct 28, 2022 | The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in vers... |
| CVE-2022-3401 | HIGH | 8.8 | 1.6% | Oct 28, 2022 | The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include ... |
| CVE-2022-43233 | HIGH | 7.2 | 0.8% | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_... |
| CVE-2022-43232 | HIGH | 7.2 | 0.8% | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_... |
| CVE-2022-43231 | HIGH | 7.2 | 1.1% | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_w... |
| CVE-2022-43230 | HIGH | 7.2 | 0.8% | Oct 28, 2022 | Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter ... |
| CVE-2022-43229 | HIGH | 7.2 | 1.1% | Oct 28, 2022 | Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter ... |
| CVE-2022-43228 | HIGH | 7.2 | 0.8% | Oct 28, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /... |
| CVE-2022-41648 | CRITICAL | 9.8 | 0.7% | Oct 28, 2022 | The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC... |
| CVE-2022-41636 | HIGH | 7.5 | 0.4% | Oct 28, 2022 | Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted ... |
| CVE-2022-3228 | MEDIUM | 6.5 | 0.3% | Oct 28, 2022 | Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing... |
| CVE-2022-2475 | HIGH | 8.8 | 0.6% | Oct 28, 2022 | Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Comman... |
| CVE-2022-2474 | HIGH | 8 | 0.7% | Oct 28, 2022 | Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” ... |
| CVE-2022-43170 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_con... |
| CVE-2022-43169 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/use... |
| CVE-2022-43168 | CRITICAL | 9.8 | 0.8% | Oct 28, 2022 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now