2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2569 | MEDIUM | 5.5 | 0.1% | Aug 24, 2022 | The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session d... |
| CVE-2022-2234 | HIGH | 8.8 | 41.5% | Aug 24, 2022 | An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating sy... |
| CVE-2022-20122 | CRITICAL | 9.8 | 0.4% | Aug 24, 2022 | The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be fre... |
| CVE-2022-37153 | MEDIUM | 6.1 | 1.4% | Aug 24, 2022 | An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.logi... |
| CVE-2022-36633 | HIGH | 8.8 | 49.5% | Aug 24, 2022 | Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ss... |
| CVE-2022-33172 | MEDIUM | 5.5 | 0.2% | Aug 24, 2022 | de.fac2 1.34 allows bypassing the User Presence protection mechanism when there is malware on the victim's PC. |
| CVE-2022-27812 | HIGH | 7.5 | 0.7% | Aug 24, 2022 | Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific for... |
| CVE-2022-38089 | MEDIUM | 5.4 | 0.8% | Aug 24, 2022 | Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-ad... |
| CVE-2022-38080 | MEDIUM | 5.4 | 0.8% | Aug 24, 2022 | Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel... |
| CVE-2022-38078 | CRITICAL | 9.8 | 1.9% | Aug 24, 2022 | Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially craft... |
| CVE-2022-37333 | HIGH | 8.8 | 1.2% | Aug 24, 2022 | SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0... |
| CVE-2022-37418 | MEDIUM | 6.4 | 0.9% | Aug 24, 2022 | The Remote Keyless Entry (RKE) receiving unit on certain Nissan, Kia, and Hyundai vehicles through 2017 allows remote at... |
| CVE-2022-37305 | MEDIUM | 6.4 | 0.9% | Aug 24, 2022 | The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform ... |
| CVE-2022-36945 | MEDIUM | 6.4 | 0.9% | Aug 24, 2022 | The Remote Keyless Entry (RKE) receiving unit on certain Mazda vehicles through 2020 allows remote attackers to perform ... |
| CVE-2022-25903 | HIGH | 7.5 | 1.1% | Aug 24, 2022 | The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) via the ExtensionObjects and Variants objects, wh... |
| CVE-2022-24375 | HIGH | 7.5 | 1.2% | Aug 24, 2022 | The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excess... |
| CVE-2022-38132 | HIGH | 8.8 | 0.6% | Aug 24, 2022 | Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and ... |
| CVE-2022-31676 | HIGH | 7.8 | 0.5% | Aug 23, 2022 | VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with loc... |
| CVE-2022-2938 | HIGH | 7.8 | 0.3% | Aug 23, 2022 | A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by de... |
| CVE-2022-38463 | MEDIUM | 6.1 | 2.3% | Aug 23, 2022 | ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality. |
| CVE-2022-38172 | MEDIUM | 6.1 | 0.5% | Aug 23, 2022 | ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performanc... |
| CVE-2022-35115 | CRITICAL | 9.8 | 0.7% | Aug 23, 2022 | IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the sear... |
| CVE-2022-1513 | HIGH | 8.8 | 0.5% | Aug 23, 2022 | A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution wh... |
| CVE-2022-38665 | MEDIUM | 6.5 | 0.7% | Aug 23, 2022 | Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration fi... |
| CVE-2022-38664 | MEDIUM | 5.4 | 0.6% | Aug 23, 2022 | Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Confi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now