2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42150 | CRITICAL | 10 | 0.9% | Oct 19, 2023 | TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configura... |
| CVE-2022-47583 | CRITICAL | 9.8 | 1.1% | Oct 19, 2023 | Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal. |
| CVE-2022-37830 | CRITICAL | 9.6 | 0.7% | Oct 19, 2023 | Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-32755 | CRITICAL | 9.1 | 0.7% | Oct 14, 2023 | IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML d... |
| CVE-2022-36276 | CRITICAL | 9.8 | 0.8% | Oct 4, 2023 | TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The expl... |
| CVE-2022-47893 | CRITICAL | 9.8 | 1.2% | Oct 3, 2023 | There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a... |
| CVE-2022-47186 | CRITICAL | 9.1 | 0.6% | Sep 28, 2023 | There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/... |
| CVE-2022-48605 | CRITICAL | 9.8 | 0.4% | Sep 25, 2023 | Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect co... |
| CVE-2022-4039 | CRITICAL | 9.8 | 0.8% | Sep 22, 2023 | A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured manage... |
| CVE-2022-3874 | CRITICAL | 9.1 | 2.2% | Sep 22, 2023 | A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the forem... |
| CVE-2022-47558 | CRITICAL | 9.8 | 0.5% | Sep 19, 2023 | Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of t... |
| CVE-2022-28357 | CRITICAL | 9.8 | 1.0% | Sep 19, 2023 | NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action fro... |
| CVE-2022-33164 | CRITICAL | 9.1 | 1.5% | Sep 8, 2023 | IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker cou... |
| CVE-2022-48565 | CRITICAL | 9.8 | 4.3% | Aug 22, 2023 | An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity ... |
| CVE-2022-48522 | CRITICAL | 9.8 | 2.0% | Aug 22, 2023 | In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or loc... |
| CVE-2022-48174 | CRITICAL | 9.8 | 3.0% | Aug 22, 2023 | There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles... |
| CVE-2022-45611 | CRITICAL | 9.8 | 0.9% | Aug 22, 2023 | An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via cap... |
| CVE-2022-36648 | CRITICAL | 10 | 1.4% | Aug 22, 2023 | The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allo... |
| CVE-2022-24989 | CRITICAL | 9.8 | 31.9% | Aug 20, 2023 | TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskst... |
| CVE-2022-29887 | CRITICAL | 9.6 | 0.6% | Aug 11, 2023 | Cross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3 may allow an unauthentic... |
| CVE-2022-40510 | CRITICAL | 9.8 | 0.4% | Aug 8, 2023 | Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. |
| CVE-2022-40609 | CRITICAL | 9.8 | 1.8% | Aug 2, 2023 | IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the sys... |
| CVE-2022-39986 | CRITICAL | 9.8 | 98.7% | Aug 1, 2023 | A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary comma... |
| CVE-2022-42183 | CRITICAL | 9.1 | 0.7% | Jul 31, 2023 | Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Server-Side Request Forgery (SSRF). |
| CVE-2022-4924 | CRITICAL | 9.6 | 0.5% | Jul 29, 2023 | Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the render... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now