2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2471 | CRITICAL | 9.8 | 1.2% | Sep 15, 2022 | Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-... |
| CVE-2022-37266 | CRITICAL | 9.8 | 1.0% | Sep 15, 2022 | Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js... |
| CVE-2022-37257 | CRITICAL | 9.8 | 1.1% | Sep 15, 2022 | Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVer... |
| CVE-2022-3224 | MEDIUM | 6.1 | 0.6% | Sep 15, 2022 | Misinterpretation of Input in GitHub repository ionicabizau/parse-url prior to 8.1.0. |
| CVE-2022-38789 | CRITICAL | 9.1 | 0.9% | Sep 15, 2022 | An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and ... |
| CVE-2022-38788 | MEDIUM | 4.3 | 0.5% | Sep 15, 2022 | An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pa... |
| CVE-2022-3222 | MEDIUM | 5.5 | 0.6% | Sep 15, 2022 | Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV. |
| CVE-2022-3221 | HIGH | 8.8 | 0.5% | Sep 15, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3. |
| CVE-2022-31735 | MEDIUM | 6.1 | 0.4% | Sep 15, 2022 | OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601)... |
| CVE-2022-40738 | MEDIUM | 6.5 | 0.6% | Sep 15, 2022 | An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_DescriptorListWriter::Acti... |
| CVE-2022-40737 | MEDIUM | 6.5 | 0.6% | Sep 15, 2022 | An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4_StdcFileByteStream::W... |
| CVE-2022-40736 | MEDIUM | 6.5 | 0.6% | Sep 15, 2022 | An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in AP4_CttsAtom::Create in Core/Ap4Ct... |
| CVE-2022-38595 | HIGH | 7.2 | 0.7% | Sep 15, 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi... |
| CVE-2022-38594 | HIGH | 7.2 | 0.7% | Sep 15, 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi... |
| CVE-2022-38352 | CRITICAL | 9.8 | 20.2% | Sep 15, 2022 | ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Sto... |
| CVE-2022-38323 | HIGH | 7.2 | 0.9% | Sep 15, 2022 | Event Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /Royal_E... |
| CVE-2022-40734 | MEDIUM | 6.5 | 4.1% | Sep 14, 2022 | UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversa... |
| CVE-2022-40476 | MEDIUM | 5.5 | 0.3% | Sep 14, 2022 | A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could ... |
| CVE-2022-40439 | MEDIUM | 6.5 | 0.6% | Sep 14, 2022 | An memory leak issue was discovered in AP4_StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers t... |
| CVE-2022-40438 | MEDIUM | 6.5 | 0.6% | Sep 14, 2022 | Buffer overflow vulnerability in function AP4_MemoryByteStream::WritePartial in mp42aac in Bento4 v1.6.0-639, allows att... |
| CVE-2022-40365 | MEDIUM | 6.1 | 0.5% | Sep 14, 2022 | Cross site scripting (XSS) vulnerability in ouqiang gocron through 1.5.3, allows attackers to execute arbitrary code via... |
| CVE-2022-38308 | CRITICAL | 9.8 | 20.3% | Sep 14, 2022 | TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter... |
| CVE-2022-38301 | HIGH | 8.8 | 1.1% | Sep 14, 2022 | Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories... |
| CVE-2022-37724 | MEDIUM | 6.1 | 0.5% | Sep 14, 2022 | Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XS... |
| CVE-2022-2977 | HIGH | 7.8 | 0.2% | Sep 14, 2022 | A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TP... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now