2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38619 | CRITICAL | 9.8 | 0.9% | Sep 21, 2022 | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /S... |
| CVE-2022-40357 | CRITICAL | 9.8 | 1.2% | Sep 20, 2022 | A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_user... |
| CVE-2022-32882 | CRITICAL | 9.8 | 0.7% | Sep 20, 2022 | This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An app ... |
| CVE-2022-32863 | CRITICAL | 9.8 | 0.8% | Sep 20, 2022 | A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monter... |
| CVE-2022-32788 | CRITICAL | 9.8 | 2.0% | Sep 20, 2022 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 a... |
| CVE-2022-40009 | CRITICAL | 9.8 | 1.0% | Sep 20, 2022 | SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c. |
| CVE-2022-40008 | CRITICAL | 9.8 | 1.0% | Sep 20, 2022 | SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c. |
| CVE-2022-41138 | CRITICAL | 9.8 | 1.7% | Sep 20, 2022 | In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution. |
| CVE-2022-37265 | CRITICAL | 9.8 | 1.1% | Sep 20, 2022 | Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js. |
| CVE-2022-38916 | CRITICAL | 9.8 | 16.3% | Sep 20, 2022 | A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload maliciou... |
| CVE-2022-37204 | CRITICAL | 9.8 | 1.0% | Sep 20, 2022 | Final CMS 5.1.0 is vulnerable to SQL Injection. |
| CVE-2022-2177 | CRITICAL | 9.4 | 0.6% | Sep 20, 2022 | Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2. |
| CVE-2022-39956 | CRITICAL | 9.8 | 0.9% | Sep 20, 2022 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submit... |
| CVE-2022-39955 | CRITICAL | 9.8 | 1.1% | Sep 20, 2022 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTT... |
| CVE-2022-38545 | CRITICAL | 9.6 | 32.9% | Sep 19, 2022 | Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute a... |
| CVE-2022-38509 | CRITICAL | 9.8 | 0.8% | Sep 19, 2022 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budg... |
| CVE-2022-37032 | CRITICAL | 9.1 | 1.5% | Sep 19, 2022 | An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of servi... |
| CVE-2022-28321 | CRITICAL | 9.8 | 1.2% | Sep 19, 2022 | The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_acce... |
| CVE-2022-0143 | CRITICAL | 9.8 | 0.5% | Sep 19, 2022 | When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all ... |
| CVE-2022-23768 | CRITICAL | 9.8 | 0.8% | Sep 19, 2022 | This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use thi... |
| CVE-2022-23767 | CRITICAL | 9.8 | 0.8% | Sep 19, 2022 | This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also i... |
| CVE-2022-40980 | CRITICAL | 9.1 | 1.1% | Sep 19, 2022 | A potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow ... |
| CVE-2022-40144 | CRITICAL | 9.8 | 2.1% | Sep 19, 2022 | A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the prod... |
| CVE-2022-3218 | CRITICAL | 9.8 | 73.5% | Sep 19, 2022 | Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism... |
| CVE-2022-40812 | CRITICAL | 9.8 | 1.0% | Sep 19, 2022 | The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now