2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34292 | HIGH | 7.1 | 0.3% | Apr 27, 2023 | Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/cr... |
| CVE-2022-31647 | HIGH | 7.1 | 0.3% | Apr 27, 2023 | Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 AP... |
| CVE-2022-45456 | HIGH | 7.5 | 0.3% | Apr 26, 2023 | Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macO... |
| CVE-2022-44232 | HIGH | 7.5 | 0.7% | Apr 26, 2023 | libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of serv... |
| CVE-2022-27978 | HIGH | 7.5 | 1.1% | Apr 26, 2023 | Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a... |
| CVE-2022-25277 | HIGH | 7.2 | 1.4% | Apr 26, 2023 | Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading a... |
| CVE-2022-25275 | HIGH | 7.5 | 0.7% | Apr 26, 2023 | In some situations, the Image module does not correctly check access to image files not stored in the standard public fi... |
| CVE-2022-25273 | HIGH | 7.5 | 0.6% | Apr 26, 2023 | Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to impro... |
| CVE-2022-41739 | HIGH | 8.4 | 0.2% | Apr 26, 2023 | IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs ru... |
| CVE-2022-36769 | HIGH | 7.2 | 0.9% | Apr 26, 2023 | IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can ... |
| CVE-2022-45291 | HIGH | 7.2 | 1.3% | Apr 25, 2023 | PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by inje... |
| CVE-2022-40724 | HIGH | 8.8 | 0.2% | Apr 25, 2023 | The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF... |
| CVE-2022-31244 | HIGH | 7.8 | 0.3% | Apr 25, 2023 | Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation. |
| CVE-2022-42335 | HIGH | 7.8 | 0.3% | Apr 25, 2023 | x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but... |
| CVE-2022-48476 | HIGH | 7.5 | 0.8% | Apr 24, 2023 | In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible |
| CVE-2022-45080 | HIGH | 8.8 | 0.3% | Apr 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in KrishaWeb Add Multiple Marker plugin <= 1.2 versions. |
| CVE-2022-45074 | HIGH | 8.8 | 0.3% | Apr 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For B... |
| CVE-2022-4944 | HIGH | 8.8 | 2.7% | Apr 22, 2023 | A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by th... |
| CVE-2022-47505 | HIGH | 7.8 | 0.2% | Apr 21, 2023 | The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a loc... |
| CVE-2022-36963 | HIGH | 7.2 | 8.4% | Apr 21, 2023 | The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adver... |
| CVE-2022-36788 | HIGH | 7.8 | 0.6% | Apr 20, 2023 | A heap-based buffer overflow vulnerability exists in the TriangleMesh clone functionality of Slic3r libslic3r 1.3.0 and ... |
| CVE-2022-46302 | HIGH | 8.8 | 0.4% | Apr 20, 2023 | Broad access controls could allow site users to directly interact with the system Apache installation when providing the... |
| CVE-2022-29608 | HIGH | 7.5 | 0.9% | Apr 20, 2023 | An issue was discovered in ONOS 2.5.1. An intent with a port that is an intermediate point of its path installs an inval... |
| CVE-2022-29607 | HIGH | 7.5 | 0.7% | Apr 20, 2023 | An issue was discovered in ONOS 2.5.1. Modification of an existing intent to have the same source and destination shows ... |
| CVE-2022-29605 | HIGH | 7.5 | 0.7% | Apr 20, 2023 | An issue was discovered in ONOS 2.5.1. IntentManager attempts to install the IPv6 flow rules of an intent into an OpenFl... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now