2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45786 | HIGH | 8.1 | 0.9% | Feb 4, 2023 | There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for Po... |
| CVE-2022-24895 | HIGH | 8.8 | 0.8% | Feb 3, 2023 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating us... |
| CVE-2022-24894 | HIGH | 8.8 | 0.8% | Feb 3, 2023 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache... |
| CVE-2022-23498 | HIGH | 8.8 | 1.1% | Feb 3, 2023 | Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana c... |
| CVE-2022-48165 | HIGH | 7.5 | 3.3% | Feb 3, 2023 | An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthen... |
| CVE-2022-47762 | HIGH | 7.5 | 0.9% | Feb 3, 2023 | In gin-vue-admin < 2.5.5, the download module has a Path Traversal vulnerability. |
| CVE-2022-47070 | HIGH | 7.5 | 0.9% | Feb 3, 2023 | NVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the serve... |
| CVE-2022-45588 | HIGH | 7.8 | 0.2% | Feb 3, 2023 | All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) typ... |
| CVE-2022-45496 | HIGH | 7.8 | 0.6% | Feb 3, 2023 | Buffer overflow vulnerability in function json_parse_string in sheredom json.h before commit 0825301a07cbf51653882bf2b15... |
| CVE-2022-45493 | HIGH | 7.8 | 0.2% | Feb 3, 2023 | Buffer overflow vulnerability in function json_parse_key in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc... |
| CVE-2022-45492 | HIGH | 7.8 | 0.2% | Feb 3, 2023 | Buffer overflow vulnerability in function json_parse_number in sheredom json.h before commit 0825301a07cbf51653882bf2b15... |
| CVE-2022-45491 | HIGH | 7.8 | 0.3% | Feb 3, 2023 | Buffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153... |
| CVE-2022-34138 | HIGH | 7.5 | 0.6% | Feb 3, 2023 | Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers ... |
| CVE-2022-4634 | HIGH | 7.8 | 5.3% | Feb 3, 2023 | All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vu... |
| CVE-2022-47132 | HIGH | 8.8 | 0.9% | Feb 3, 2023 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users. |
| CVE-2022-46842 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions. |
| CVE-2022-46815 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin ... |
| CVE-2022-45807 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions. |
| CVE-2022-45067 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in DevsCred Exclusive Addons Elementor plugin <= 2.6.1 versions. |
| CVE-2022-44585 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions. |
| CVE-2022-40692 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions. |
| CVE-2022-36401 | HIGH | 8.8 | 0.3% | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in TeraWallet – For WooCommerce plugin <= 1.3.24 versions. |
| CVE-2022-46604 | HIGH | 8.8 | 8.6% | Feb 2, 2023 | An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis... |
| CVE-2022-46552 | HIGH | 8.8 | 10.5% | Feb 2, 2023 | D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan... |
| CVE-2022-46965 | HIGH | 8.8 | 1.0% | Feb 2, 2023 | PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now