2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32590 | MEDIUM | 6.7 | 0.1% | Oct 7, 2022 | In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of pri... |
| CVE-2022-32589 | HIGH | 7.5 | 0.6% | Oct 7, 2022 | In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to rem... |
| CVE-2022-26475 | MEDIUM | 6.7 | 0.1% | Oct 7, 2022 | In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p... |
| CVE-2022-26474 | MEDIUM | 6.7 | 0.1% | Oct 7, 2022 | In sensorhub, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to... |
| CVE-2022-26473 | MEDIUM | 6.7 | 0.1% | Oct 7, 2022 | In vdec fmt, there is a possible use after free due to improper locking. This could lead to local escalation of privileg... |
| CVE-2022-26472 | HIGH | 7.8 | 0.1% | Oct 7, 2022 | In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation... |
| CVE-2022-26471 | HIGH | 7.8 | 0.1% | Oct 7, 2022 | In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local esca... |
| CVE-2022-26452 | MEDIUM | 6.7 | 0.1% | Oct 7, 2022 | In isp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege wit... |
| CVE-2022-42075 | CRITICAL | 9.8 | 1.1% | Oct 7, 2022 | Wedding Planner v1.0 is vulnerable to arbitrary code execution. |
| CVE-2022-42074 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=. |
| CVE-2022-42073 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=. |
| CVE-2022-41392 | MEDIUM | 5.4 | 0.6% | Oct 7, 2022 | A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts ... |
| CVE-2022-41379 | HIGH | 7.2 | 0.9% | Oct 7, 2022 | An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Managemen... |
| CVE-2022-41378 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad... |
| CVE-2022-41377 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad... |
| CVE-2022-37896 | MEDIUM | 6.1 | 0.5% | Oct 7, 2022 | A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote attacker to conduct ... |
| CVE-2022-37895 | MEDIUM | 4.9 | 0.7% | Oct 7, 2022 | An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba Instant... |
| CVE-2022-37894 | MEDIUM | 6.5 | 0.4% | Oct 7, 2022 | An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba Instant... |
| CVE-2022-37893 | HIGH | 7.8 | 0.8% | Oct 7, 2022 | An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Su... |
| CVE-2022-42092 | HIGH | 7.2 | 1.5% | Oct 7, 2022 | Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Executi... |
| CVE-2022-41515 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at... |
| CVE-2022-41514 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at... |
| CVE-2022-41513 | HIGH | 7.2 | 0.7% | Oct 7, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-41512 | HIGH | 7.2 | 0.9% | Oct 7, 2022 | An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management Sys... |
| CVE-2022-41414 | MEDIUM | 5.3 | 0.4% | Oct 7, 2022 | An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now