2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20919 | HIGH | 7.5 | 1.0% | Sep 30, 2022 | A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Softw... |
| CVE-2022-20856 | HIGH | 7.5 | 1.1% | Sep 30, 2022 | A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Ci... |
| CVE-2022-20855 | MEDIUM | 6.7 | 0.3% | Sep 30, 2022 | A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst... |
| CVE-2022-20851 | HIGH | 7.2 | 0.9% | Sep 30, 2022 | A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform ... |
| CVE-2022-20850 | HIGH | 7.1 | 0.2% | Sep 30, 2022 | A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenti... |
| CVE-2022-20848 | HIGH | 7.5 | 0.9% | Sep 30, 2022 | A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Cataly... |
| CVE-2022-20847 | HIGH | 7.5 | 1.1% | Sep 30, 2022 | A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 ... |
| CVE-2022-20844 | MEDIUM | 5.3 | 0.7% | Sep 30, 2022 | A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cis... |
| CVE-2022-20818 | HIGH | 7.8 | 0.6% | Sep 30, 2022 | Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevat... |
| CVE-2022-20810 | MEDIUM | 6.5 | 0.7% | Sep 30, 2022 | A vulnerability in the Simple Network Management Protocol (SNMP) of Cisco IOS XE Wireless Controller Software for the Ca... |
| CVE-2022-20775 | HIGH | 7.8 | 12.5% | Sep 30, 2022 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privil... |
| CVE-2022-20769 | MEDIUM | 6.5 | 0.5% | Sep 30, 2022 | A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow a... |
| CVE-2022-20728 | MEDIUM | 4.7 | 0.2% | Sep 30, 2022 | A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adja... |
| CVE-2022-20662 | MEDIUM | 6.8 | 0.3% | Sep 30, 2022 | A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker wi... |
| CVE-2022-41975 | HIGH | 7.8 | 0.2% | Sep 30, 2022 | RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI inst... |
| CVE-2022-41870 | HIGH | 7.2 | 1.2% | Sep 30, 2022 | AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app u... |
| CVE-2022-40944 | CRITICAL | 9.8 | 1.1% | Sep 30, 2022 | Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file. |
| CVE-2022-40316 | MEDIUM | 4.3 | 0.5% | Sep 30, 2022 | The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non... |
| CVE-2022-40315 | CRITICAL | 9.8 | 0.8% | Sep 30, 2022 | A limited SQL injection risk was identified in the "browse list of users" site administration page. |
| CVE-2022-40314 | CRITICAL | 9.8 | 1.5% | Sep 30, 2022 | A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified. |
| CVE-2022-40313 | HIGH | 7.1 | 0.5% | Sep 30, 2022 | Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a ... |
| CVE-2022-40277 | HIGH | 7.8 | 0.5% | Sep 30, 2022 | Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link ... |
| CVE-2022-40274 | HIGH | 7.8 | 0.4% | Sep 30, 2022 | Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a m... |
| CVE-2022-36965 | MEDIUM | 6.1 | 0.6% | Sep 30, 2022 | Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This i... |
| CVE-2022-36961 | HIGH | 8.8 | 75.2% | Sep 30, 2022 | A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now