2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36362 | HIGH | 7.5 | 0.9% | Oct 11, 2022 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCE (6ED1052-1MD08... |
| CVE-2022-36361 | CRITICAL | 9.8 | 0.9% | Oct 11, 2022 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0... |
| CVE-2022-36360 | HIGH | 7.5 | 0.3% | Oct 11, 2022 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load f... |
| CVE-2022-31766 | HIGH | 8.6 | 1.0% | Oct 11, 2022 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDC... |
| CVE-2022-31765 | HIGH | 8.8 | 0.9% | Oct 11, 2022 | Affected devices do not properly authorize the change password function of the web interface. This could allow low priv... |
| CVE-2022-37616 | CRITICAL | 9.8 | 1.5% | Oct 11, 2022 | A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) pa... |
| CVE-2022-40138 | CRITICAL | 9.8 | 0.9% | Oct 11, 2022 | An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, cou... |
| CVE-2022-35289 | CRITICAL | 9.8 | 0.9% | Oct 11, 2022 | A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c... |
| CVE-2022-32234 | CRITICAL | 9.8 | 0.9% | Oct 11, 2022 | An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1 ... |
| CVE-2022-3433 | MEDIUM | 6.5 | 0.7% | Oct 10, 2022 | The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a h... |
| CVE-2022-41749 | HIGH | 7.8 | 0.2% | Oct 10, 2022 | An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privile... |
| CVE-2022-41748 | MEDIUM | 6.7 | 0.2% | Oct 10, 2022 | A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local a... |
| CVE-2022-41747 | HIGH | 7.8 | 0.2% | Oct 10, 2022 | An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a... |
| CVE-2022-41746 | CRITICAL | 9.1 | 1.0% | Oct 10, 2022 | A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on a... |
| CVE-2022-41745 | HIGH | 7 | 0.7% | Oct 10, 2022 | An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create a specially crafted... |
| CVE-2022-41744 | HIGH | 7 | 0.2% | Oct 10, 2022 | A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component coul... |
| CVE-2022-3220 | MEDIUM | 4.8 | 0.5% | Oct 10, 2022 | The Advanced Comment Form WordPress plugin before 1.2.1 does not sanitise and escape its settings, allowing high privile... |
| CVE-2022-3209 | MEDIUM | 6.1 | 0.5% | Oct 10, 2022 | The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_sl... |
| CVE-2022-3208 | MEDIUM | 6.5 | 0.3% | Oct 10, 2022 | The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make... |
| CVE-2022-3207 | MEDIUM | 4.8 | 0.5% | Oct 10, 2022 | The Simple File List WordPress plugin before 4.4.12 does not sanitise and escape some of its settings, which could allow... |
| CVE-2022-3154 | HIGH | 7.1 | 0.3% | Oct 10, 2022 | The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before ... |
| CVE-2022-3137 | MEDIUM | 5.4 | 0.5% | Oct 10, 2022 | The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any a... |
| CVE-2022-3136 | MEDIUM | 4.8 | 0.5% | Oct 10, 2022 | The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2022-39288 | HIGH | 7.5 | 59.2% | Oct 10, 2022 | fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of s... |
| CVE-2022-36063 | CRITICAL | 9.8 | 1.5% | Oct 10, 2022 | Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now