2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43305 | CRITICAL | 9.8 | 1.0% | Nov 7, 2022 | The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third part... |
| CVE-2022-43304 | CRITICAL | 9.8 | 1.0% | Nov 7, 2022 | The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party... |
| CVE-2022-43303 | CRITICAL | 9.8 | 1.0% | Nov 7, 2022 | The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third par... |
| CVE-2022-42920 | CRITICAL | 9.8 | 2.8% | Nov 7, 2022 | Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However... |
| CVE-2022-37865 | CRITICAL | 9.1 | 1.8% | Nov 7, 2022 | With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fl... |
| CVE-2022-3481 | CRITICAL | 9.8 | 3.7% | Nov 7, 2022 | The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using ... |
| CVE-2022-3463 | CRITICAL | 9.8 | 1.2% | Nov 7, 2022 | The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries a... |
| CVE-2022-44797 | CRITICAL | 9.8 | 1.2% | Nov 7, 2022 | btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other Bitcoin-related products, mishandles witn... |
| CVE-2022-44796 | CRITICAL | 9.8 | 0.7% | Nov 7, 2022 | An issue was discovered in Object First Ootbi BETA build 1.0.7.712. The authorization service has a flow that allows get... |
| CVE-2022-42905 | CRITICAL | 9.1 | 2.0% | Nov 7, 2022 | In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 cl... |
| CVE-2022-44544 | CRITICAL | 9.8 | 0.8% | Nov 6, 2022 | Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PD... |
| CVE-2022-3868 | CRITICAL | 9.8 | 0.5% | Nov 5, 2022 | A vulnerability classified as critical has been found in SourceCodester Sanitization Management System. Affected is an u... |
| CVE-2022-39344 | CRITICAL | 9.8 | 1.9% | Nov 4, 2022 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS Thre... |
| CVE-2022-31691 | CRITICAL | 9.8 | 2.4% | Nov 4, 2022 | Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI... |
| CVE-2022-3023 | CRITICAL | 9.8 | 0.6% | Nov 4, 2022 | Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3. |
| CVE-2022-38168 | CRITICAL | 9.1 | 1.1% | Nov 3, 2022 | Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote un... |
| CVE-2022-42744 | CRITICAL | 9.8 | 1.2% | Nov 3, 2022 | CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is pos... |
| CVE-2022-40747 | CRITICAL | 9.1 | 0.9% | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing X... |
| CVE-2022-22425 | CRITICAL | 9.8 | 1.1% | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbi... |
| CVE-2022-39323 | CRITICAL | 9.8 | 34.3% | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr... |
| CVE-2022-43109 | CRITICAL | 9.8 | 3.7% | Nov 3, 2022 | D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettin... |
| CVE-2022-43108 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewal... |
| CVE-2022-43107 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagem... |
| CVE-2022-43106 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWi... |
| CVE-2022-43105 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGus... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now