2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43104 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWire... |
| CVE-2022-43103 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand funct... |
| CVE-2022-43102 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime f... |
| CVE-2022-43101 | CRITICAL | 9.8 | 0.9% | Nov 3, 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName... |
| CVE-2022-39382 | CRITICAL | 9.8 | 1.5% | Nov 3, 2022 | Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/core@3.0.0 || 3.0.1` users that use `... |
| CVE-2022-24936 | CRITICAL | 9.1 | 0.8% | Nov 2, 2022 | Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrit... |
| CVE-2022-3575 | CRITICAL | 9.8 | 0.7% | Nov 2, 2022 | Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload wi... |
| CVE-2022-39353 | CRITICAL | 9.8 | 1.2% | Nov 2, 2022 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom par... |
| CVE-2022-3827 | CRITICAL | 9.8 | 0.8% | Nov 2, 2022 | A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the ... |
| CVE-2022-39379 | CRITICAL | 9.8 | 44.7% | Nov 2, 2022 | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ... |
| CVE-2022-38381 | CRITICAL | 9.8 | 0.7% | Nov 2, 2022 | An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all version... |
| CVE-2022-27586 | CRITICAL | 9.8 | 1.2% | Nov 1, 2022 | Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged r... |
| CVE-2022-27585 | CRITICAL | 9.8 | 1.2% | Nov 1, 2022 | Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an... |
| CVE-2022-27584 | CRITICAL | 9.8 | 1.2% | Nov 1, 2022 | Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain acce... |
| CVE-2022-27582 | CRITICAL | 9.8 | 1.2% | Nov 1, 2022 | Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain ... |
| CVE-2022-42813 | CRITICAL | 9.8 | 0.9% | Nov 1, 2022 | A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. ... |
| CVE-2022-42808 | CRITICAL | 9.8 | 2.0% | Nov 1, 2022 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and... |
| CVE-2022-32941 | CRITICAL | 9.8 | 1.3% | Nov 1, 2022 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura ... |
| CVE-2022-3789 | CRITICAL | 9.8 | 0.6% | Nov 1, 2022 | A vulnerability has been found in Tim Campus Confession Wall and classified as critical. Affected by this vulnerability ... |
| CVE-2022-41552 | CRITICAL | 9.8 | 0.6% | Nov 1, 2022 | Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analy... |
| CVE-2022-2572 | CRITICAL | 9.8 | 0.7% | Nov 1, 2022 | In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible t... |
| CVE-2022-44542 | CRITICAL | 9.8 | 1.1% | Nov 1, 2022 | lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object dest... |
| CVE-2022-40296 | CRITICAL | 9.8 | 0.6% | Oct 31, 2022 | The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with u... |
| CVE-2022-40293 | CRITICAL | 9.8 | 0.6% | Oct 31, 2022 | The application was vulnerable to a session fixation that could be used hijack accounts. |
| CVE-2022-40289 | CRITICAL | 9 | 0.6% | Oct 31, 2022 | The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functio... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now