2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39989 | CRITICAL | 9.8 | 0.8% | Apr 26, 2023 | An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor ... |
| CVE-2022-48477 | CRITICAL | 9.8 | 0.5% | Apr 24, 2023 | In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing |
| CVE-2022-29606 | CRITICAL | 9.8 | 1.0% | Apr 20, 2023 | An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading t... |
| CVE-2022-29604 | CRITICAL | 9.8 | 1.0% | Apr 20, 2023 | An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which ... |
| CVE-2022-46640 | CRITICAL | 9.8 | 2.4% | Apr 18, 2023 | Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a ... |
| CVE-2022-48312 | CRITICAL | 9.1 | 0.4% | Apr 16, 2023 | The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability m... |
| CVE-2022-34128 | CRITICAL | 9.8 | 7.7% | Apr 16, 2023 | The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data ... |
| CVE-2022-2525 | CRITICAL | 9.8 | 0.8% | Apr 15, 2023 | Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. |
| CVE-2022-3748 | CRITICAL | 9.8 | 0.9% | Apr 14, 2023 | Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affect... |
| CVE-2022-45174 | CRITICAL | 9.8 | 1.0% | Apr 14, 2023 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML User... |
| CVE-2022-45173 | CRITICAL | 9.8 | 1.0% | Apr 14, 2023 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur und... |
| CVE-2022-47027 | CRITICAL | 9.8 | 1.5% | Apr 14, 2023 | Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal sto... |
| CVE-2022-45064 | CRITICAL | 9 | 1.1% | Apr 13, 2023 | The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-... |
| CVE-2022-33259 | CRITICAL | 9.8 | 0.4% | Apr 13, 2023 | Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received. |
| CVE-2022-33211 | CRITICAL | 9.8 | 0.4% | Apr 13, 2023 | memory corruption in modem due to improper check while calculating size of serialized CoAP message |
| CVE-2022-25745 | CRITICAL | 9.8 | 0.4% | Apr 13, 2023 | Memory corruption in modem due to improper input validation while handling the incoming CoAP message |
| CVE-2022-25740 | CRITICAL | 9.8 | 0.4% | Apr 13, 2023 | Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of ... |
| CVE-2022-25678 | CRITICAL | 9.8 | 0.4% | Apr 13, 2023 | Memory correction in modem due to buffer overwrite during coap connection |
| CVE-2022-41331 | CRITICAL | 9.8 | 1.3% | Apr 11, 2023 | A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before ver... |
| CVE-2022-46709 | CRITICAL | 9.8 | 0.8% | Apr 10, 2023 | A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16.... |
| CVE-2022-31890 | CRITICAL | 9.8 | 1.5% | Apr 5, 2023 | SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb... |
| CVE-2022-4939 | CRITICAL | 9.8 | 2.1% | Apr 5, 2023 | THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, ... |
| CVE-2022-43939 | CRITICAL | 9.8 | 92.3% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security ... |
| CVE-2022-38923 | CRITICAL | 9.8 | 1.1% | Apr 3, 2023 | BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' fi... |
| CVE-2022-38922 | CRITICAL | 9.8 | 1.0% | Apr 3, 2023 | BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'us... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now