2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31324 | MEDIUM | 6.5 | 0.4% | Sep 13, 2022 | An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 ... |
| CVE-2022-31322 | HIGH | 7.8 | 0.3% | Sep 13, 2022 | Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files us... |
| CVE-2022-40623 | HIGH | 8.8 | 0.5% | Sep 13, 2022 | The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 does not utilize anti-CSRF tokens, which, ... |
| CVE-2022-40622 | HIGH | 8.8 | 0.7% | Sep 13, 2022 | The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and doe... |
| CVE-2022-40621 | HIGH | 7.5 | 0.7% | Sep 13, 2022 | Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP... |
| CVE-2022-39821 | HIGH | 7.5 | 0.6% | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The we... |
| CVE-2022-39819 | HIGH | 8.8 | 1.4% | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execut... |
| CVE-2022-39817 | HIGH | 8.8 | 0.7% | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker.... |
| CVE-2022-39816 | MEDIUM | 6.5 | 0.5% | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit confi... |
| CVE-2022-39815 | CRITICAL | 9.8 | 2.1% | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated ... |
| CVE-2022-39814 | MEDIUM | 6.1 | 0.4% | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter. |
| CVE-2022-38637 | CRITICAL | 9.8 | 4.6% | Sep 13, 2022 | Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Pa... |
| CVE-2022-38497 | MEDIUM | 5.5 | 0.3% | Sep 13, 2022 | LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69. |
| CVE-2022-38496 | MEDIUM | 5.5 | 0.3% | Sep 13, 2022 | LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp. |
| CVE-2022-38495 | HIGH | 7.8 | 0.3% | Sep 13, 2022 | LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c. |
| CVE-2022-38329 | MEDIUM | 4.3 | 0.4% | Sep 13, 2022 | A CSRF vulnerability in Shopxian CMS 3.0.0 could allow an unauthenticated, remote attacker to craft a malicious link, po... |
| CVE-2022-38307 | MEDIUM | 5.5 | 0.3% | Sep 13, 2022 | LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::fil... |
| CVE-2022-38306 | HIGH | 7.8 | 0.3% | Sep 13, 2022 | LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc. |
| CVE-2022-36768 | HIGH | 7.8 | 0.2% | Sep 13, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout c... |
| CVE-2022-35637 | MEDIUM | 6.5 | 1.0% | Sep 13, 2022 | IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering ... |
| CVE-2022-34356 | HIGH | 7.8 | 0.2% | Sep 13, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel... |
| CVE-2022-34336 | MEDIUM | 5.4 | 0.4% | Sep 13, 2022 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2022-22483 | MEDIUM | 6.5 | 0.8% | Sep 13, 2022 | IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some s... |
| CVE-2022-22330 | MEDIUM | 5.3 | 0.7% | Sep 13, 2022 | IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the H... |
| CVE-2022-22329 | MEDIUM | 4.3 | 0.5% | Sep 13, 2022 | IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be ab... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now