2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40288 | CRITICAL | 9 | 0.6% | Oct 31, 2022 | The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, w... |
| CVE-2022-40287 | CRITICAL | 9 | 0.6% | Oct 31, 2022 | The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messa... |
| CVE-2022-40190 | CRITICAL | 9.6 | 0.7% | Oct 31, 2022 | SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web applicati... |
| CVE-2022-41779 | CRITICAL | 9.8 | 1.1% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper veri... |
| CVE-2022-41772 | CRITICAL | 9.8 | 24.9% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters u... |
| CVE-2022-41657 | CRITICAL | 9.8 | 20.9% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized... |
| CVE-2022-41629 | CRITICAL | 9.1 | 0.6% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprun... |
| CVE-2022-40202 | CRITICAL | 9.8 | 1.2% | Oct 31, 2022 | The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper au... |
| CVE-2022-38142 | CRITICAL | 9.8 | 18.2% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through... |
| CVE-2022-31692 | CRITICAL | 9.8 | 3.4% | Oct 31, 2022 | Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass v... |
| CVE-2022-28763 | CRITICAL | 9.6 | 1.1% | Oct 31, 2022 | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL... |
| CVE-2022-27583 | CRITICAL | 9.1 | 0.6% | Oct 31, 2022 | A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2... |
| CVE-2022-40471 | CRITICAL | 9.8 | 19.4% | Oct 31, 2022 | Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p... |
| CVE-2022-3774 | CRITICAL | 9.1 | 1.1% | Oct 31, 2022 | A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue i... |
| CVE-2022-3254 | CRITICAL | 9.8 | 5.1% | Oct 31, 2022 | The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters befor... |
| CVE-2022-3771 | CRITICAL | 9.8 | 0.5% | Oct 31, 2022 | A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of... |
| CVE-2022-37623 | CRITICAL | 9.8 | 1.1% | Oct 31, 2022 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th... |
| CVE-2022-40741 | CRITICAL | 9.8 | 1.1% | Oct 31, 2022 | Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacke... |
| CVE-2022-3754 | CRITICAL | 9.8 | 1.1% | Oct 29, 2022 | Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8. |
| CVE-2022-2826 | CRITICAL | 9.8 | 0.8% | Oct 28, 2022 | An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting fr... |
| CVE-2022-43286 | CRITICAL | 9.8 | 0.9% | Oct 28, 2022 | Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_j... |
| CVE-2022-37621 | CRITICAL | 9.8 | 1.0% | Oct 28, 2022 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th... |
| CVE-2022-41648 | CRITICAL | 9.8 | 0.7% | Oct 28, 2022 | The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC... |
| CVE-2022-43168 | CRITICAL | 9.8 | 0.8% | Oct 28, 2022 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter. |
| CVE-2022-39366 | CRITICAL | 9.8 | 0.9% | Oct 28, 2022 | DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadat... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now