2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3385 | CRITICAL | 9.8 | 1.2% | Oct 27, 2022 | Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker ... |
| CVE-2022-43340 | HIGH | 8.8 | 0.4% | Oct 27, 2022 | A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and... |
| CVE-2022-39978 | HIGH | 7.2 | 1.1% | Oct 27, 2022 | Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in... |
| CVE-2022-39977 | HIGH | 7.2 | 1.1% | Oct 27, 2022 | Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in... |
| CVE-2022-39976 | CRITICAL | 9.8 | 0.8% | Oct 27, 2022 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id pa... |
| CVE-2022-0074 | HIGH | 8.8 | 1.2% | Oct 27, 2022 | Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Containe... |
| CVE-2022-0073 | HIGH | 8.8 | 8.7% | Oct 27, 2022 | Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dash... |
| CVE-2022-0072 | MEDIUM | 5.8 | 1.0% | Oct 27, 2022 | Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards... |
| CVE-2022-32407 | MEDIUM | 6.1 | 0.5% | Oct 27, 2022 | Softr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the C... |
| CVE-2022-43367 | CRITICAL | 9.8 | 5.2% | Oct 27, 2022 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function... |
| CVE-2022-43366 | HIGH | 7.5 | 0.8% | Oct 27, 2022 | IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to access sensitive information via the checkLoginUser, at... |
| CVE-2022-43365 | HIGH | 7.5 | 0.8% | Oct 27, 2022 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a buffer overflow in the formSetDebugCfg function. This vulnerabi... |
| CVE-2022-43364 | HIGH | 7.5 | 0.7% | Oct 27, 2022 | An access control issue in the password reset page of IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to a... |
| CVE-2022-42055 | MEDIUM | 6.5 | 1.7% | Oct 27, 2022 | Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via ... |
| CVE-2022-42054 | MEDIUM | 5.4 | 0.5% | Oct 27, 2022 | Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.0... |
| CVE-2022-40875 | HIGH | 7.5 | 0.8% | Oct 27, 2022 | Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo. |
| CVE-2022-40874 | HIGH | 7.5 | 0.8% | Oct 27, 2022 | Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, whic... |
| CVE-2022-31898 | MEDIUM | 6.8 | 15.9% | Oct 27, 2022 | gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulne... |
| CVE-2022-41996 | HIGH | 8.8 | 0.5% | Oct 27, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leadin... |
| CVE-2022-40184 | MEDIUM | 4.8 | 0.3% | Oct 27, 2022 | Incomplete filtering of JavaScript code in different configuration fields of the web based interface of the VIDEOJET mul... |
| CVE-2022-40183 | MEDIUM | 4.7 | 0.3% | Oct 27, 2022 | An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-bas... |
| CVE-2022-3725 | HIGH | 7.5 | 0.8% | Oct 27, 2022 | Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafte... |
| CVE-2022-24670 | MEDIUM | 6.5 | 0.5% | Oct 27, 2022 | An attacker can use the unrestricted LDAP queries to determine configuration entries |
| CVE-2022-24669 | MEDIUM | 6.5 | 0.4% | Oct 27, 2022 | It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be ... |
| CVE-2022-3095 | CRITICAL | 9.8 | 0.9% | Oct 27, 2022 | The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now