2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-48363 | HIGH | 7.5 | 1.2% | Feb 26, 2023 | In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Dra... |
| CVE-2022-48362 | HIGH | 8.8 | 8.7% | Feb 25, 2023 | Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName ... |
| CVE-2022-44310 | HIGH | 7.5 | 0.7% | Feb 24, 2023 | In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obt... |
| CVE-2022-1607 | HIGH | 8.8 | 0.2% | Feb 24, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plan... |
| CVE-2022-4492 | HIGH | 7.5 | 0.6% | Feb 23, 2023 | The undertow client is not checking the server identity presented by the server certificate in https connections. This i... |
| CVE-2022-48341 | HIGH | 8.8 | 1.0% | Feb 23, 2023 | ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Adminis... |
| CVE-2022-45600 | HIGH | 8.8 | 2.3% | Feb 22, 2023 | Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers... |
| CVE-2022-43873 | HIGH | 8.8 | 0.6% | Feb 22, 2023 | An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute c... |
| CVE-2022-2883 | HIGH | 7.5 | 1.0% | Feb 22, 2023 | In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Serv... |
| CVE-2022-48282 | HIGH | 7.2 | 1.0% | Feb 21, 2023 | Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitra... |
| CVE-2022-3353 | HIGH | 7.5 | 1.1% | Feb 21, 2023 | A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products. An attac... |
| CVE-2022-31394 | HIGH | 7.5 | 1.1% | Feb 21, 2023 | Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party ... |
| CVE-2022-48340 | HIGH | 7.5 | 0.9% | Feb 21, 2023 | In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free. |
| CVE-2022-48339 | HIGH | 7.8 | 1.1% | Feb 20, 2023 | An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-iste... |
| CVE-2022-48338 | HIGH | 7.3 | 1.6% | Feb 20, 2023 | An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local comm... |
| CVE-2022-44216 | HIGH | 7.5 | 0.7% | Feb 20, 2023 | Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without kno... |
| CVE-2022-47909 | HIGH | 7.8 | 0.4% | Feb 20, 2023 | Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <=... |
| CVE-2022-46836 | HIGH | 8.8 | 1.1% | Feb 20, 2023 | PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Check... |
| CVE-2022-46303 | HIGH | 7.5 | 1.1% | Feb 20, 2023 | Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allo... |
| CVE-2022-40231 | HIGH | 8.8 | 0.6% | Feb 17, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenti... |
| CVE-2022-34351 | HIGH | 7.5 | 0.4% | Feb 17, 2023 | IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain secu... |
| CVE-2022-43930 | HIGH | 7.5 | 0.5% | Feb 17, 2023 | IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive informa... |
| CVE-2022-41734 | HIGH | 7.5 | 0.5% | Feb 17, 2023 | IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a det... |
| CVE-2022-40232 | HIGH | 8.8 | 0.5% | Feb 17, 2023 | IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to ... |
| CVE-2022-20803 | HIGH | 7.5 | 1.1% | Feb 17, 2023 | A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unaut... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now