2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41828 | HIGH | 8.1 | 1.5% | Sep 29, 2022 | In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Facto... |
| CVE-2022-3364 | HIGH | 7.5 | 1.0% | Sep 29, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3. |
| CVE-2022-39232 | MEDIUM | 4.3 | 1.0% | Sep 29, 2022 | Discourse is an open source discussion platform. Starting with version 2.9.0.beta5 and prior to version 2.9.0.beta10, an... |
| CVE-2022-40472 | HIGH | 8 | 0.9% | Sep 29, 2022 | ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vu... |
| CVE-2022-39226 | MEDIUM | 4.3 | 0.8% | Sep 29, 2022 | Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be... |
| CVE-2022-36068 | MEDIUM | 4.3 | 0.7% | Sep 29, 2022 | Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be... |
| CVE-2022-36066 | HIGH | 7.2 | 1.6% | Sep 29, 2022 | Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be... |
| CVE-2022-35137 | MEDIUM | 5.4 | 0.5% | Sep 29, 2022 | DGIOT Lightweight industrial IoT v4.5.4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. |
| CVE-2022-33880 | CRITICAL | 9.8 | 0.7% | Sep 29, 2022 | hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the t... |
| CVE-2022-39266 | CRITICAL | 9.8 | 1.1% | Sep 29, 2022 | isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, ... |
| CVE-2022-40887 | CRITICAL | 9.8 | 0.9% | Sep 29, 2022 | SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection. |
| CVE-2022-40879 | MEDIUM | 6.1 | 1.1% | Sep 29, 2022 | kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.' |
| CVE-2022-29504 | — | — | — | Sep 29, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2022-29503 | CRITICAL | 9.8 | 1.2% | Sep 29, 2022 | A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1... |
| CVE-2022-40931 | MEDIUM | 6.1 | 0.5% | Sep 29, 2022 | dutchcoders Transfer.sh 1.4.0 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-39168 | HIGH | 7.5 | 0.7% | Sep 29, 2022 | IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID... |
| CVE-2022-39254 | MEDIUM | 6.5 | 0.6% | Sep 29, 2022 | matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a u... |
| CVE-2022-39252 | HIGH | 7.5 | 0.5% | Sep 29, 2022 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encr... |
| CVE-2022-38732 | HIGH | 7.5 | 0.6% | Sep 29, 2022 | SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain typ... |
| CVE-2022-40408 | MEDIUM | 5.4 | 0.4% | Sep 29, 2022 | FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into... |
| CVE-2022-40407 | HIGH | 8.8 | 1.2% | Sep 29, 2022 | A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a c... |
| CVE-2022-40890 | HIGH | 7.5 | 0.9% | Sep 29, 2022 | A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service. |
| CVE-2022-40363 | MEDIUM | 5.5 | 0.3% | Sep 29, 2022 | A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 a... |
| CVE-2022-39250 | HIGH | 7.5 | 0.9% | Sep 29, 2022 | Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0... |
| CVE-2022-40475 | CRITICAL | 9.8 | 3.5% | Sep 29, 2022 | TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/download... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now