2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25916 | HIGH | 7.8 | 1.1% | Feb 1, 2023 | Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitizatio... |
| CVE-2022-25906 | HIGH | 7.8 | 1.1% | Feb 1, 2023 | All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other chec... |
| CVE-2022-4062 | HIGH | 7.8 | 0.2% | Feb 1, 2023 | A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software function... |
| CVE-2022-42973 | HIGH | 7.8 | 0.2% | Feb 1, 2023 | A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local att... |
| CVE-2022-42972 | HIGH | 7.8 | 0.2% | Feb 1, 2023 | A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege e... |
| CVE-2022-47768 | HIGH | 7.5 | 1.2% | Feb 1, 2023 | Serenissima Informatica Fast Checkin 1.0 is vulnerable to Directory Traversal. |
| CVE-2022-48161 | HIGH | 7.5 | 0.8% | Feb 1, 2023 | Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.... |
| CVE-2022-45494 | HIGH | 7.8 | 0.4% | Jan 31, 2023 | Buffer overflow vulnerability in function json_parse_object in sheredom json.h before commit 0825301a07cbf51653882bf2b15... |
| CVE-2022-32984 | HIGH | 7.5 | 1.0% | Jan 31, 2023 | BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale a... |
| CVE-2022-47700 | HIGH | 7.5 | 0.5% | Jan 31, 2023 | COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerab... |
| CVE-2022-46835 | HIGH | 7.5 | 0.9% | Jan 31, 2023 | IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, Identity... |
| CVE-2022-44645 | HIGH | 8.8 | 1.9% | Jan 31, 2023 | In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code... |
| CVE-2022-39059 | HIGH | 7.5 | 1.0% | Jan 31, 2023 | ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unau... |
| CVE-2022-25881 | HIGH | 7.5 | 1.6% | Jan 31, 2023 | This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request... |
| CVE-2022-4441 | HIGH | 8.8 | 0.6% | Jan 31, 2023 | Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u... |
| CVE-2022-4041 | HIGH | 8.8 | 0.6% | Jan 31, 2023 | Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u... |
| CVE-2022-30421 | HIGH | 7.8 | 0.3% | Jan 31, 2023 | Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive info... |
| CVE-2022-48176 | HIGH | 7.8 | 0.4% | Jan 31, 2023 | Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94... |
| CVE-2022-32748 | HIGH | 8.3 | 0.1% | Jan 30, 2023 | A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to ... |
| CVE-2022-32747 | HIGH | 8.1 | 0.3% | Jan 30, 2023 | A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of ... |
| CVE-2022-32521 | HIGH | 8.8 | 0.5% | Jan 30, 2023 | A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the s... |
| CVE-2022-32512 | HIGH | 7.8 | 0.3% | Jan 30, 2023 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause... |
| CVE-2022-22732 | HIGH | 7.5 | 0.3% | Jan 30, 2023 | A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the r... |
| CVE-2022-4794 | HIGH | 7.5 | 0.8% | Jan 30, 2023 | The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (... |
| CVE-2022-4680 | HIGH | 7.2 | 1.0% | Jan 30, 2023 | The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now