2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3269 | CRITICAL | 9.8 | 0.7% | Sep 23, 2022 | Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7. |
| CVE-2022-26112 | CRITICAL | 9.8 | 1.3% | Sep 23, 2022 | In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in un... |
| CVE-2022-39227 | CRITICAL | 9.1 | 3.6% | Sep 23, 2022 | python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authenticati... |
| CVE-2022-35951 | CRITICAL | 9.8 | 2.7% | Sep 23, 2022 | Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Inte... |
| CVE-2022-37235 | CRITICAL | 9.8 | 1.0% | Sep 23, 2022 | Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow... |
| CVE-2022-37232 | CRITICAL | 9.8 | 1.0% | Sep 23, 2022 | Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow ... |
| CVE-2022-38573 | CRITICAL | 9.8 | 1.4% | Sep 23, 2022 | 10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function. |
| CVE-2022-40089 | CRITICAL | 9.8 | 1.9% | Sep 22, 2022 | A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code vi... |
| CVE-2022-40087 | CRITICAL | 9.8 | 1.3% | Sep 22, 2022 | Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_co... |
| CVE-2022-36934 | CRITICAL | 9.8 | 1.9% | Sep 22, 2022 | An integer overflow in WhatsApp could result in remote code execution in an established video call. |
| CVE-2022-31937 | CRITICAL | 9.8 | 1.0% | Sep 22, 2022 | Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd. |
| CVE-2022-3268 | CRITICAL | 9.8 | 1.0% | Sep 22, 2022 | Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2. |
| CVE-2022-40186 | CRITICAL | 9.1 | 0.8% | Sep 22, 2022 | An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine wa... |
| CVE-2022-28802 | CRITICAL | 9.9 | 1.0% | Sep 21, 2022 | Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScr... |
| CVE-2022-40030 | CRITICAL | 9.8 | 1.2% | Sep 21, 2022 | SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId p... |
| CVE-2022-30578 | CRITICAL | 9 | 0.8% | Sep 21, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that al... |
| CVE-2022-30577 | CRITICAL | 9 | 0.7% | Sep 21, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a l... |
| CVE-2022-41241 | CRITICAL | 9.1 | 0.7% | Sep 21, 2022 | Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2022-41238 | CRITICAL | 9.8 | 0.9% | Sep 21, 2022 | A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger build... |
| CVE-2022-41237 | CRITICAL | 9.8 | 1.3% | Sep 21, 2022 | Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ty... |
| CVE-2022-41226 | CRITICAL | 9.8 | 0.8% | Sep 21, 2022 | Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML extern... |
| CVE-2022-37026 | CRITICAL | 9.8 | 1.1% | Sep 21, 2022 | In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in... |
| CVE-2022-0495 | CRITICAL | 9.4 | 0.6% | Sep 21, 2022 | The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticate... |
| CVE-2022-2315 | CRITICAL | 9.4 | 0.7% | Sep 21, 2022 | Database Software Accreditation Tracking/Presentation Module product before version 2 has an unauthenticated SQL Injecti... |
| CVE-2022-41220 | CRITICAL | 9.8 | 1.4% | Sep 21, 2022 | md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now