2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2052 | CRITICAL | 9.8 | 0.6% | Oct 17, 2022 | Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use t... |
| CVE-2022-42980 | CRITICAL | 9.8 | 0.8% | Oct 17, 2022 | go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key. |
| CVE-2022-42968 | CRITICAL | 9.8 | 1.1% | Oct 16, 2022 | Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. |
| CVE-2022-41436 | CRITICAL | 9.1 | 0.7% | Oct 14, 2022 | An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the U... |
| CVE-2022-38418 | CRITICAL | 9.8 | 80.0% | Oct 14, 2022 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a... |
| CVE-2022-35712 | CRITICAL | 9.8 | 36.8% | Oct 14, 2022 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflo... |
| CVE-2022-35711 | CRITICAL | 9.8 | 73.5% | Oct 14, 2022 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflo... |
| CVE-2022-35710 | CRITICAL | 9.8 | 42.6% | Oct 14, 2022 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overfl... |
| CVE-2022-35690 | CRITICAL | 9.8 | 72.2% | Oct 14, 2022 | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overfl... |
| CVE-2022-41477 | CRITICAL | 9.1 | 1.1% | Oct 14, 2022 | A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.... |
| CVE-2022-41581 | CRITICAL | 9.1 | 0.4% | Oct 14, 2022 | The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability... |
| CVE-2022-41580 | CRITICAL | 9.8 | 0.5% | Oct 14, 2022 | The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability... |
| CVE-2022-41578 | CRITICAL | 9.8 | 0.5% | Oct 14, 2022 | The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root p... |
| CVE-2022-38986 | CRITICAL | 9.1 | 0.5% | Oct 14, 2022 | The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploi... |
| CVE-2022-38983 | CRITICAL | 9.8 | 0.6% | Oct 14, 2022 | The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may resu... |
| CVE-2022-38982 | CRITICAL | 9.8 | 0.5% | Oct 14, 2022 | The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock ... |
| CVE-2022-38980 | CRITICAL | 9.8 | 0.5% | Oct 14, 2022 | The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful... |
| CVE-2022-42064 | CRITICAL | 9.8 | 1.1% | Oct 14, 2022 | Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploa... |
| CVE-2022-3504 | CRITICAL | 9.8 | 0.6% | Oct 14, 2022 | A vulnerability was found in SourceCodester Sanitization Management System and classified as critical. This issue affect... |
| CVE-2022-3439 | CRITICAL | 9.8 | 0.6% | Oct 14, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0. |
| CVE-2022-37602 | CRITICAL | 9.8 | 1.6% | Oct 14, 2022 | Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js. |
| CVE-2022-32177 | CRITICAL | 9 | 0.9% | Oct 14, 2022 | In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to executio... |
| CVE-2022-41391 | CRITICAL | 9.8 | 0.8% | Oct 13, 2022 | OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. |
| CVE-2022-41390 | CRITICAL | 9.8 | 0.8% | Oct 13, 2022 | OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php. |
| CVE-2022-39303 | CRITICAL | 9.8 | 0.7% | Oct 13, 2022 | Ree6 is a moderation bot. This vulnerability allows manipulation of SQL queries. This issue has been patched in version ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now