2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38932 | HIGH | 7.8 | 0.3% | Sep 27, 2022 | readelf in ToaruOS 2.0.1 has a global overflow allowing RCE when parsing a crafted ELF file. |
| CVE-2022-38335 | MEDIUM | 5.4 | 0.7% | Sep 27, 2022 | Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template mo... |
| CVE-2022-37346 | CRITICAL | 9.8 | 1.0% | Sep 27, 2022 | EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability wh... |
| CVE-2022-37209 | HIGH | 8.8 | 1.1% | Sep 27, 2022 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters... |
| CVE-2022-37193 | HIGH | 7.4 | 0.5% | Sep 27, 2022 | Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo d... |
| CVE-2022-37028 | MEDIUM | 5.4 | 0.4% | Sep 27, 2022 | ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker ... |
| CVE-2022-34326 | HIGH | 7.5 | 0.6% | Sep 27, 2022 | In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b... |
| CVE-2022-31367 | HIGH | 8.8 | 1.3% | Sep 27, 2022 | Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses. |
| CVE-2022-23006 | MEDIUM | 6.7 | 0.3% | Sep 27, 2022 | A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk i... |
| CVE-2022-39258 | HIGH | 8.2 | 0.6% | Sep 27, 2022 | mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger... |
| CVE-2022-39256 | HIGH | 8 | 1.2% | Sep 27, 2022 | Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote ... |
| CVE-2022-3298 | HIGH | 7.5 | 0.9% | Sep 26, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8. |
| CVE-2022-40099 | HIGH | 7.2 | 0.8% | Sep 26, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-40098 | HIGH | 7.2 | 0.8% | Sep 26, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-40097 | HIGH | 7.2 | 0.8% | Sep 26, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-40050 | CRITICAL | 9.8 | 0.9% | Sep 26, 2022 | ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1. |
| CVE-2022-30004 | CRITICAL | 9.8 | 1.4% | Sep 26, 2022 | Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing ... |
| CVE-2022-3290 | HIGH | 7.5 | 0.7% | Sep 26, 2022 | Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8. |
| CVE-2022-30003 | MEDIUM | 5.4 | 0.5% | Sep 26, 2022 | Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register ... |
| CVE-2022-3272 | HIGH | 7.5 | 1.4% | Sep 26, 2022 | Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8. |
| CVE-2022-22058 | HIGH | 7.8 | 0.2% | Sep 26, 2022 | Memory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Snapdragon Comp... |
| CVE-2022-40784 | HIGH | 8.8 | 0.9% | Sep 26, 2022 | Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2... |
| CVE-2022-40044 | MEDIUM | 5.4 | 0.6% | Sep 26, 2022 | Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Nam... |
| CVE-2022-40043 | HIGH | 8.8 | 1.1% | Sep 26, 2022 | Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter ... |
| CVE-2022-3201 | MEDIUM | 5.4 | 0.6% | Sep 26, 2022 | Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now