2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22223 | HIGH | 7.5 | 0.8% | Oct 18, 2022 | On QFX10000 Series devices using Juniper Networks Junos OS when configured as transit IP/MPLS penultimate hop popping (P... |
| CVE-2022-22220 | MEDIUM | 5.9 | 0.4% | Oct 18, 2022 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks J... |
| CVE-2022-22219 | MEDIUM | 5.9 | 0.6% | Oct 18, 2022 | Due to the Improper Handling of an Unexpected Data Type in the processing of EVPN routes on Juniper Networks Junos OS an... |
| CVE-2022-22218 | HIGH | 7.5 | 0.4% | Oct 18, 2022 | On SRX Series devices, an Improper Check for Unusual or Exceptional Conditions when using Certificate Management Protoco... |
| CVE-2022-22211 | HIGH | 7.5 | 0.6% | Oct 18, 2022 | A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows... |
| CVE-2022-22208 | MEDIUM | 5.9 | 0.4% | Oct 18, 2022 | A Use After Free vulnerability in the Routing Protocol Daemon (rdp) of Juniper Networks Junos OS and Junos OS Evolved al... |
| CVE-2022-22201 | HIGH | 7.5 | 0.6% | Oct 18, 2022 | An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (P... |
| CVE-2022-22192 | HIGH | 7.5 | 0.7% | Oct 18, 2022 | An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolve... |
| CVE-2022-3569 | HIGH | 7.8 | 0.7% | Oct 17, 2022 | Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalat... |
| CVE-2022-3158 | HIGH | 8.8 | 3.2% | Oct 17, 2022 | Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation ... |
| CVE-2022-42147 | MEDIUM | 6.1 | 0.4% | Oct 17, 2022 | kkFileView 4.0 is vulnerable to Cross Site Scripting (XSS) via controller\ Filecontroller.java. |
| CVE-2022-42143 | HIGH | 7.2 | 0.8% | Oct 17, 2022 | Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php. |
| CVE-2022-42142 | HIGH | 7.2 | 1.0% | Oct 17, 2022 | Online Tours & Travels Management System v1.0 is vulnerable to Arbitrary code execution via ip/tour/admin/operations/upd... |
| CVE-2022-41431 | MEDIUM | 5.4 | 0.6% | Oct 17, 2022 | xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. T... |
| CVE-2022-40606 | MEDIUM | 6.1 | 0.4% | Oct 17, 2022 | MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a differ... |
| CVE-2022-3552 | HIGH | 7.2 | 44.0% | Oct 17, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1. |
| CVE-2022-3368 | HIGH | 8.8 | 0.8% | Oct 17, 2022 | A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write a... |
| CVE-2022-38743 | HIGH | 8.8 | 1.3% | Oct 17, 2022 | Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access c... |
| CVE-2022-42149 | CRITICAL | 9.8 | 2.2% | Oct 17, 2022 | kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java. |
| CVE-2022-41139 | MEDIUM | 5.4 | 0.5% | Oct 17, 2022 | MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execut... |
| CVE-2022-40605 | MEDIUM | 6.1 | 0.4% | Oct 17, 2022 | MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a differ... |
| CVE-2022-3517 | HIGH | 7.5 | 1.7% | Oct 17, 2022 | A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when... |
| CVE-2022-3421 | HIGH | 7.3 | 0.1% | Oct 17, 2022 | An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned ... |
| CVE-2022-3382 | HIGH | 7.5 | 0.7% | Oct 17, 2022 | HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an... |
| CVE-2022-3567 | MEDIUM | 6.4 | 0.3% | Oct 17, 2022 | A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function in... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now