2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3732 | CRITICAL | 9.8 | 0.4% | Oct 28, 2022 | A vulnerability was found in seccome Ehoney and classified as critical. Affected by this issue is some unknown functiona... |
| CVE-2022-3731 | CRITICAL | 9.8 | 0.4% | Oct 28, 2022 | A vulnerability has been found in seccome Ehoney and classified as critical. Affected by this vulnerability is an unknow... |
| CVE-2022-3730 | CRITICAL | 9.8 | 0.4% | Oct 28, 2022 | A vulnerability, which was classified as critical, was found in seccome Ehoney. Affected is an unknown function of the f... |
| CVE-2022-3729 | CRITICAL | 9.8 | 0.4% | Oct 28, 2022 | A vulnerability, which was classified as critical, has been found in seccome Ehoney. This issue affects some unknown pro... |
| CVE-2022-26884 | MEDIUM | 6.5 | 1.5% | Oct 28, 2022 | Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher. |
| CVE-2022-3616 | HIGH | 7.5 | 0.4% | Oct 28, 2022 | Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequen... |
| CVE-2022-37915 | CRITICAL | 9.8 | 1.6% | Oct 28, 2022 | A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauth... |
| CVE-2022-37914 | CRITICAL | 9.8 | 1.3% | Oct 28, 2022 | Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauth... |
| CVE-2022-37913 | CRITICAL | 9.8 | 1.3% | Oct 28, 2022 | Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauth... |
| CVE-2022-33859 | CRITICAL | 9.8 | 0.3% | Oct 28, 2022 | A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast ... |
| CVE-2022-31678 | CRITICAL | 9.1 | 8.1% | Oct 28, 2022 | VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V dep... |
| CVE-2022-3379 | HIGH | 7.8 | 0.2% | Oct 27, 2022 | Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a ... |
| CVE-2022-3378 | HIGH | 7.8 | 0.2% | Oct 27, 2022 | Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a... |
| CVE-2022-41773 | HIGH | 8.8 | 7.9% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIA... |
| CVE-2022-41702 | MEDIUM | 5.4 | 11.1% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi... |
| CVE-2022-41701 | MEDIUM | 5.4 | 11.1% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi... |
| CVE-2022-41651 | MEDIUM | 5.4 | 11.1% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi... |
| CVE-2022-41627 | HIGH | 7.6 | 0.1% | Oct 27, 2022 | The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encr... |
| CVE-2022-41555 | MEDIUM | 5.4 | 11.1% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi... |
| CVE-2022-41133 | HIGH | 8.8 | 26.6% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_... |
| CVE-2022-40967 | HIGH | 8.8 | 7.7% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoT... |
| CVE-2022-40965 | MEDIUM | 5.4 | 11.1% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi... |
| CVE-2022-40876 | CRITICAL | 9.8 | 1.8% | Oct 27, 2022 | In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can ... |
| CVE-2022-3387 | MEDIUM | 5.3 | 14.0% | Oct 27, 2022 | Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could r... |
| CVE-2022-3386 | CRITICAL | 9.8 | 1.2% | Oct 27, 2022 | Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now