2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43938 | HIGH | 8.8 | 26.6% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a... |
| CVE-2022-43773 | HIGH | 8.8 | 22.2% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed w... |
| CVE-2022-43769 | HIGH | 7.2 | 97.7% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain w... |
| CVE-2022-38072 | HIGH | 8.8 | 1.1% | Apr 3, 2023 | An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master ... |
| CVE-2022-36440 | HIGH | 7.5 | 1.6% | Apr 3, 2023 | A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can malic... |
| CVE-2022-42447 | HIGH | 8.8 | 0.4% | Apr 2, 2023 | HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote a... |
| CVE-2022-47192 | HIGH | 8.8 | 1.3% | Mar 31, 2023 | Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users... |
| CVE-2022-47191 | HIGH | 8.8 | 1.1% | Mar 31, 2023 | Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with mod... |
| CVE-2022-47188 | HIGH | 7.5 | 0.9% | Mar 31, 2023 | There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the... |
| CVE-2022-46021 | HIGH | 7.5 | 0.6% | Mar 31, 2023 | X-Man 1.0 has a SQL injection vulnerability, which can cause data leakage. |
| CVE-2022-4899 | HIGH | 7.5 | 1.6% | Mar 31, 2023 | A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line ... |
| CVE-2022-4744 | HIGH | 7.8 | 0.5% | Mar 30, 2023 | A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the devic... |
| CVE-2022-47542 | HIGH | 8.8 | 0.6% | Mar 30, 2023 | Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privil... |
| CVE-2022-23522 | HIGH | 8.8 | 0.9% | Mar 30, 2023 | MindsDB is an open source machine learning platform. An unsafe extraction is being performed using `shutil.unpack_archiv... |
| CVE-2022-30351 | HIGH | 7.5 | 0.6% | Mar 30, 2023 | PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to correctly remove redacted inf... |
| CVE-2022-30350 | HIGH | 7.5 | 0.7% | Mar 30, 2023 | Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Onl... |
| CVE-2022-3787 | HIGH | 7.8 | 0.2% | Mar 29, 2023 | A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root ... |
| CVE-2022-44370 | HIGH | 7.8 | 0.4% | Mar 29, 2023 | NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856 |
| CVE-2022-45355 | HIGH | 7.2 | 0.6% | Mar 29, 2023 | Auth. (admin+) SQL Injection (SQLi) vulnerability in ThimPress WP Pipes plugin <= 1.33 versions. |
| CVE-2022-43650 | HIGH | 7.1 | 23.0% | Mar 29, 2023 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR ... |
| CVE-2022-43649 | HIGH | 7.8 | 1.1% | Mar 29, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.... |
| CVE-2022-43648 | HIGH | 8.8 | 0.9% | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3... |
| CVE-2022-43647 | HIGH | 8.8 | 1.0% | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8... |
| CVE-2022-43646 | HIGH | 8.8 | 1.0% | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8... |
| CVE-2022-43645 | HIGH | 8.8 | 1.0% | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now