2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30579 | HIGH | 8.4 | 0.5% | Sep 20, 2022 | The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfi... |
| CVE-2022-41138 | CRITICAL | 9.8 | 1.7% | Sep 20, 2022 | In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution. |
| CVE-2022-40262 | HIGH | 8.2 | 0.3% | Sep 20, 2022 | A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages... |
| CVE-2022-40261 | HIGH | 8.2 | 0.3% | Sep 20, 2022 | An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in Syste... |
| CVE-2022-40250 | HIGH | 8.8 | 0.4% | Sep 20, 2022 | An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in Syste... |
| CVE-2022-40246 | HIGH | 7.2 | 0.5% | Sep 20, 2022 | A potential attacker can write one byte by arbitrary address at the time of the PEI phase (only during S3 resume boot mo... |
| CVE-2022-39974 | HIGH | 7.5 | 0.8% | Sep 20, 2022 | WASM3 v0.5.0 was discovered to contain a segmentation fault via the component op_Select_i32_srs in wasm3/source/m3_exec.... |
| CVE-2022-38956 | MEDIUM | 5.3 | 0.2% | Sep 20, 2022 | An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker... |
| CVE-2022-38955 | HIGH | 7.5 | 0.3% | Sep 20, 2022 | An exploitable firmware modification vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attac... |
| CVE-2022-38340 | HIGH | 7.2 | 0.9% | Sep 20, 2022 | Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via t... |
| CVE-2022-37265 | CRITICAL | 9.8 | 1.1% | Sep 20, 2022 | Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js. |
| CVE-2022-37259 | HIGH | 7.5 | 1.0% | Sep 20, 2022 | A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js... |
| CVE-2022-37205 | HIGH | 8.8 | 1.1% | Sep 20, 2022 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters... |
| CVE-2022-2154 | — | — | — | Sep 20, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-34345. Reason: This candidate is a reservation d... |
| CVE-2022-26873 | HIGH | 8.2 | 0.4% | Sep 20, 2022 | A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages... |
| CVE-2022-38916 | CRITICAL | 9.8 | 16.3% | Sep 20, 2022 | A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload maliciou... |
| CVE-2022-37204 | CRITICAL | 9.8 | 1.0% | Sep 20, 2022 | Final CMS 5.1.0 is vulnerable to SQL Injection. |
| CVE-2022-35196 | HIGH | 8.8 | 0.4% | Sep 20, 2022 | TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php. |
| CVE-2022-32167 | MEDIUM | 5.4 | 0.4% | Sep 20, 2022 | Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functi... |
| CVE-2022-40955 | HIGH | 8.8 | 2.0% | Sep 20, 2022 | In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL... |
| CVE-2022-3245 | MEDIUM | 6.1 | 0.5% | Sep 20, 2022 | HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS... |
| CVE-2022-3242 | MEDIUM | 6.1 | 1.4% | Sep 20, 2022 | Code Injection in GitHub repository microweber/microweber prior to 1.3.2. |
| CVE-2022-3005 | MEDIUM | 5.4 | 0.5% | Sep 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
| CVE-2022-2177 | CRITICAL | 9.4 | 0.6% | Sep 20, 2022 | Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2. |
| CVE-2022-3079 | HIGH | 7.5 | 0.7% | Sep 20, 2022 | Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpag... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now