2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39035 | MEDIUM | 6.1 | 0.5% | Sep 28, 2022 | Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An ... |
| CVE-2022-39034 | MEDIUM | 6.5 | 1.2% | Sep 28, 2022 | Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special ch... |
| CVE-2022-39033 | CRITICAL | 9.8 | 1.5% | Sep 28, 2022 | Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special c... |
| CVE-2022-39032 | HIGH | 8.8 | 0.7% | Sep 28, 2022 | Smart eVision has an improper privilege management vulnerability. A remote attacker with general user privilege can expl... |
| CVE-2022-39031 | MEDIUM | 5.3 | 0.6% | Sep 28, 2022 | Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit ... |
| CVE-2022-39030 | HIGH | 7.5 | 0.7% | Sep 28, 2022 | smart eVision has inadequate authorization for system information query function. An unauthenticated remote attacker, wh... |
| CVE-2022-39029 | MEDIUM | 6.5 | 0.6% | Sep 28, 2022 | Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privileg... |
| CVE-2022-38699 | MEDIUM | 5.9 | 0.3% | Sep 28, 2022 | Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A phys... |
| CVE-2022-40497 | HIGH | 8.8 | 1.2% | Sep 28, 2022 | Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code exe... |
| CVE-2022-41604 | HIGH | 8.8 | 0.6% | Sep 27, 2022 | Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs beca... |
| CVE-2022-41571 | CRITICAL | 9.8 | 0.8% | Sep 27, 2022 | An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur. |
| CVE-2022-41570 | CRITICAL | 9.8 | 0.7% | Sep 27, 2022 | An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur. |
| CVE-2022-40878 | HIGH | 8.8 | 23.2% | Sep 27, 2022 | In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to ach... |
| CVE-2022-40877 | CRITICAL | 9.8 | 1.1% | Sep 27, 2022 | Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter. |
| CVE-2022-40817 | MEDIUM | 4.3 | 0.4% | Sep 27, 2022 | Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents w... |
| CVE-2022-40816 | MEDIUM | 6.5 | 0.7% | Sep 27, 2022 | Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that custo... |
| CVE-2022-40354 | HIGH | 7.2 | 0.8% | Sep 27, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-40353 | HIGH | 7.2 | 0.8% | Sep 27, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-40352 | HIGH | 7.2 | 0.7% | Sep 27, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-40199 | LOW | 2.7 | 1.0% | Sep 27, 2022 | Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 ... |
| CVE-2022-3324 | HIGH | 7.8 | 0.5% | Sep 27, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598. |
| CVE-2022-3323 | HIGH | 7.5 | 30.7% | Sep 27, 2022 | An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet ... |
| CVE-2022-3303 | MEDIUM | 4.7 | 0.3% | Sep 27, 2022 | A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL poi... |
| CVE-2022-39835 | MEDIUM | 5.3 | 0.5% | Sep 27, 2022 | An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct ... |
| CVE-2022-38975 | MEDIUM | 5.4 | 0.5% | Sep 27, 2022 | DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to in... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now