2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43019 | CRITICAL | 9.8 | 1.8% | Oct 19, 2022 | OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax fu... |
| CVE-2022-1523 | CRITICAL | 9.1 | 0.5% | Oct 19, 2022 | Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to a write-what-where condition, which could allow an atta... |
| CVE-2022-43406 | CRITICAL | 9.9 | 1.1% | Oct 19, 2022 | A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier al... |
| CVE-2022-43405 | CRITICAL | 9.9 | 1.2% | Oct 19, 2022 | A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attack... |
| CVE-2022-43404 | CRITICAL | 9.9 | 1.1% | Oct 19, 2022 | A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructor... |
| CVE-2022-43403 | CRITICAL | 9.9 | 1.4% | Oct 19, 2022 | A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin ... |
| CVE-2022-43402 | CRITICAL | 9.9 | 1.2% | Oct 19, 2022 | A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pi... |
| CVE-2022-43401 | CRITICAL | 9.9 | 1.2% | Oct 19, 2022 | A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Sc... |
| CVE-2022-43184 | CRITICAL | 9.8 | 1.7% | Oct 19, 2022 | D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.... |
| CVE-2022-41415 | CRITICAL | 9.8 | 1.3% | Oct 19, 2022 | Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vul... |
| CVE-2022-25748 | CRITICAL | 9.8 | 0.4% | Oct 19, 2022 | Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapd... |
| CVE-2022-25720 | CRITICAL | 9.8 | 0.4% | Oct 19, 2022 | Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute... |
| CVE-2022-25719 | CRITICAL | 9.1 | 0.5% | Oct 19, 2022 | Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto... |
| CVE-2022-25718 | CRITICAL | 9.8 | 0.4% | Oct 19, 2022 | Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Sna... |
| CVE-2022-25687 | CRITICAL | 9.8 | 0.3% | Oct 19, 2022 | memory corruption in video due to buffer overflow while parsing asf clips in Snapdragon Auto, Snapdragon Compute, Snapdr... |
| CVE-2022-39428 | CRITICAL | 9.8 | 36.5% | Oct 18, 2022 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). ... |
| CVE-2022-21587 | CRITICAL | 9.8 | 98.3% | Oct 18, 2022 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). ... |
| CVE-2022-39198 | CRITICAL | 9.8 | 2.4% | Oct 18, 2022 | A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malic... |
| CVE-2022-43260 | CRITICAL | 9.8 | 0.8% | Oct 18, 2022 | Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime fu... |
| CVE-2022-41544 | CRITICAL | 9.8 | 9.4% | Oct 18, 2022 | GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete... |
| CVE-2022-33874 | CRITICAL | 9.8 | 2.8% | Oct 18, 2022 | An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] i... |
| CVE-2022-33873 | CRITICAL | 9.8 | 2.5% | Oct 18, 2022 | An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] i... |
| CVE-2022-33872 | CRITICAL | 9.8 | 2.8% | Oct 18, 2022 | An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] i... |
| CVE-2022-40684 | CRITICAL | 9.8 | 100.0% | Oct 18, 2022 | An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an... |
| CVE-2022-35846 | CRITICAL | 9.8 | 0.7% | Oct 18, 2022 | An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 th... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now