2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28883 | HIGH | 7.5 | 0.5% | Aug 23, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack functi... |
| CVE-2022-28882 | HIGH | 7.5 | 0.4% | Aug 23, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go i... |
| CVE-2022-35278 | MEDIUM | 6.1 | 1.4% | Aug 23, 2022 | In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a maliciou... |
| CVE-2022-37223 | CRITICAL | 9.8 | 0.8% | Aug 23, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list. |
| CVE-2022-37199 | CRITICAL | 9.8 | 0.8% | Aug 23, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list. |
| CVE-2022-36261 | CRITICAL | 9.1 | 1.0% | Aug 23, 2022 | An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server w... |
| CVE-2022-35203 | HIGH | 7.2 | 2.0% | Aug 23, 2022 | An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system informat... |
| CVE-2022-2956 | MEDIUM | 6.1 | 0.5% | Aug 23, 2022 | A vulnerability classified as problematic has been found in ConsoleTVs Noxen. Affected is an unknown function of the fil... |
| CVE-2022-28817 | — | — | — | Aug 23, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: No impact could be verified. Notes: none |
| CVE-2022-1989 | MEDIUM | 5.3 | 0.7% | Aug 23, 2022 | All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a... |
| CVE-2022-2796 | MEDIUM | 4.8 | 1.5% | Aug 23, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.4. |
| CVE-2022-36350 | MEDIUM | 5.4 | 0.5% | Aug 23, 2022 | Stored cross-site scripting vulnerability in PukiWiki versions 1.3.1 to 1.5.3 allows a remote attacker to inject an arbi... |
| CVE-2022-34486 | HIGH | 7.2 | 1.1% | Aug 23, 2022 | Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administ... |
| CVE-2022-27637 | MEDIUM | 6.1 | 0.5% | Aug 23, 2022 | Reflected cross-site scripting vulnerability in PukiWiki versions 1.5.1 to 1.5.3 allows a remote attacker to inject an a... |
| CVE-2022-25888 | HIGH | 7.5 | 1.0% | Aug 23, 2022 | The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of rece... |
| CVE-2022-25761 | HIGH | 7.5 | 1.1% | Aug 23, 2022 | The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) du... |
| CVE-2022-25304 | HIGH | 7.5 | 1.1% | Aug 23, 2022 | All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missin... |
| CVE-2022-25302 | HIGH | 7.5 | 0.7% | Aug 23, 2022 | All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing handler for failed c... |
| CVE-2022-25231 | HIGH | 7.5 | 1.0% | Aug 23, 2022 | The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA ... |
| CVE-2022-24381 | HIGH | 7.5 | 0.7% | Aug 23, 2022 | All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing limitation on the nu... |
| CVE-2022-24298 | HIGH | 7.5 | 0.8% | Aug 23, 2022 | All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for... |
| CVE-2022-21208 | HIGH | 7.5 | 1.2% | Aug 23, 2022 | The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number... |
| CVE-2022-2829 | MEDIUM | 5.4 | 0.7% | Aug 23, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
| CVE-2022-35733 | CRITICAL | 9.8 | 1.2% | Aug 23, 2022 | Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA100... |
| CVE-2022-34919 | CRITICAL | 9.8 | 1.4% | Aug 23, 2022 | The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authentic... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now