2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38411 | HIGH | 7.8 | 0.6% | Sep 16, 2022 | Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by a Heap-based Buffer Overflow vulner... |
| CVE-2022-38410 | MEDIUM | 5.5 | 0.3% | Sep 16, 2022 | Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerabili... |
| CVE-2022-38409 | MEDIUM | 5.5 | 0.3% | Sep 16, 2022 | Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerabili... |
| CVE-2022-38408 | HIGH | 7.8 | 0.4% | Sep 16, 2022 | Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vuln... |
| CVE-2022-37775 | MEDIUM | 6.1 | 0.7% | Sep 16, 2022 | Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printa... |
| CVE-2022-36402 | MEDIUM | 5.5 | 0.4% | Sep 16, 2022 | An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of ... |
| CVE-2022-40337 | HIGH | 8.8 | 1.1% | Sep 16, 2022 | OASES (aka Open Aviation Strategic Engineering System) 8.8.0.2 allows attackers to execute arbitrary code via the Open P... |
| CVE-2022-38878 | HIGH | 7.2 | 0.9% | Sep 16, 2022 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/inde... |
| CVE-2022-38877 | HIGH | 7.2 | 1.1% | Sep 16, 2022 | Garage Management System v1.0 is vulnerable to Arbitrary code execution via ip/garage/php_action/editProductImage.php?id... |
| CVE-2022-37248 | MEDIUM | 5.4 | 0.5% | Sep 16, 2022 | Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php. |
| CVE-2022-35195 | HIGH | 7.2 | 1.1% | Sep 16, 2022 | TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdow... |
| CVE-2022-35193 | HIGH | 7.2 | 0.9% | Sep 16, 2022 | TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php. |
| CVE-2022-38833 | HIGH | 7.2 | 0.8% | Sep 16, 2022 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent... |
| CVE-2022-38832 | HIGH | 7.2 | 0.9% | Sep 16, 2022 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department... |
| CVE-2022-38831 | CRITICAL | 9.8 | 1.0% | Sep 16, 2022 | Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/SetNetControlList |
| CVE-2022-38830 | CRITICAL | 9.8 | 1.0% | Sep 16, 2022 | Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setIPv6Status. |
| CVE-2022-38829 | CRITICAL | 9.8 | 1.0% | Sep 16, 2022 | Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setMacFilterCfg. |
| CVE-2022-38828 | CRITICAL | 9.8 | 19.3% | Sep 16, 2022 | TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi |
| CVE-2022-38827 | CRITICAL | 9.8 | 12.0% | Sep 16, 2022 | TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi |
| CVE-2022-38826 | CRITICAL | 9.8 | 1.1% | Sep 16, 2022 | In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi. |
| CVE-2022-38823 | CRITICAL | 9.8 | 0.9% | Sep 16, 2022 | In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample. |
| CVE-2022-37250 | MEDIUM | 5.4 | 0.5% | Sep 16, 2022 | Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount. |
| CVE-2022-3176 | HIGH | 7.8 | 0.3% | Sep 16, 2022 | There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose l... |
| CVE-2022-38846 | MEDIUM | 5.9 | 0.4% | Sep 16, 2022 | EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insec... |
| CVE-2022-38845 | MEDIUM | 6.1 | 0.6% | Sep 16, 2022 | Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s brow... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now