2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43003 | CRITICAL | 9.8 | 1.2% | Oct 26, 2022 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecur... |
| CVE-2022-43002 | CRITICAL | 9.8 | 1.2% | Oct 26, 2022 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/f... |
| CVE-2022-43001 | CRITICAL | 9.8 | 1.2% | Oct 26, 2022 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity func... |
| CVE-2022-43000 | CRITICAL | 9.8 | 1.2% | Oct 26, 2022 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/fo... |
| CVE-2022-42998 | CRITICAL | 9.8 | 1.2% | Oct 26, 2022 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd... |
| CVE-2022-43775 | CRITICAL | 9.8 | 20.6% | Oct 26, 2022 | The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to ga... |
| CVE-2022-43774 | CRITICAL | 9.8 | 0.7% | Oct 26, 2022 | The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacke... |
| CVE-2022-3674 | CRITICAL | 9.8 | 0.5% | Oct 26, 2022 | A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected... |
| CVE-2022-3671 | CRITICAL | 9.8 | 1.0% | Oct 26, 2022 | A vulnerability classified as critical was found in SourceCodester eLearning System 1.0. This vulnerability affects unkn... |
| CVE-2022-42468 | CRITICAL | 9.8 | 2.7% | Oct 26, 2022 | Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration u... |
| CVE-2022-39357 | CRITICAL | 9.8 | 1.0% | Oct 26, 2022 | Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in v... |
| CVE-2022-2422 | CRITICAL | 9.8 | 0.7% | Oct 26, 2022 | Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the bac... |
| CVE-2022-2421 | CRITICAL | 9.8 | 1.1% | Oct 26, 2022 | Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeho... |
| CVE-2022-29823 | CRITICAL | 9.8 | 1.4% | Oct 26, 2022 | Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This... |
| CVE-2022-29822 | CRITICAL | 9.8 | 0.7% | Oct 26, 2022 | Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection |
| CVE-2022-43747 | CRITICAL | 9.8 | 0.9% | Oct 26, 2022 | baramundi Management Agent (bMA) in baramundi Management Suite (bMS) 2021 R1 and R2 and 2022 R1 allows remote code execu... |
| CVE-2022-41711 | CRITICAL | 9.8 | 1.6% | Oct 25, 2022 | Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is... |
| CVE-2022-36452 | CRITICAL | 9.8 | 0.8% | Oct 25, 2022 | A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated att... |
| CVE-2022-3393 | CRITICAL | 9.8 | 1.3% | Oct 25, 2022 | The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV... |
| CVE-2022-39342 | CRITICAL | 9.8 | 0.9% | Oct 25, 2022 | OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass un... |
| CVE-2022-39341 | CRITICAL | 9.8 | 0.9% | Oct 25, 2022 | OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass un... |
| CVE-2022-39327 | CRITICAL | 9.8 | 3.2% | Oct 25, 2022 | Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulner... |
| CVE-2022-39322 | CRITICAL | 9.8 | 1.1% | Oct 25, 2022 | @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 ... |
| CVE-2022-39321 | CRITICAL | 9.9 | 1.5% | Oct 25, 2022 | GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow. The actions runner invokes the ... |
| CVE-2022-39312 | CRITICAL | 9.8 | 1.5% | Oct 25, 2022 | Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerabilit... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now