2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43519 | HIGH | 8.8 | 1.0% | Jan 5, 2023 | Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow ... |
| CVE-2022-37934 | HIGH | 7.5 | 1.8% | Jan 5, 2023 | A potential security vulnerability has been identified in HPE OfficeConnect 1820, and 1850 switch series. The vulnerabil... |
| CVE-2022-37933 | HIGH | 7.8 | 0.3% | Jan 5, 2023 | A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnera... |
| CVE-2022-48217 | HIGH | 8.1 | 0.7% | Jan 4, 2023 | The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a... |
| CVE-2022-43920 | HIGH | 8.8 | 0.5% | Jan 4, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could allow an authenticated user to gain privilege... |
| CVE-2022-25926 | HIGH | 7.8 | 1.1% | Jan 4, 2023 | Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due t... |
| CVE-2022-48216 | HIGH | 7.5 | 0.8% | Jan 4, 2023 | Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds. |
| CVE-2022-46081 | HIGH | 7.5 | 0.7% | Jan 4, 2023 | In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from continued exposure of pr... |
| CVE-2022-42435 | HIGH | 8.8 | 0.3% | Jan 4, 2023 | IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2... |
| CVE-2022-38723 | HIGH | 8.6 | 0.8% | Jan 3, 2023 | Gravitee API Management before 3.15.13 allows path traversal through HTML injection. |
| CVE-2022-2967 | HIGH | 7.5 | 0.4% | Jan 3, 2023 | Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not suffi... |
| CVE-2022-44036 | HIGH | 7.2 | 1.1% | Jan 3, 2023 | In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for adm... |
| CVE-2022-36943 | HIGH | 8.1 | 0.8% | Jan 3, 2023 | SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths... |
| CVE-2022-32664 | HIGH | 8.8 | 1.2% | Jan 3, 2023 | In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc... |
| CVE-2022-32635 | HIGH | 7.8 | 0.1% | Jan 3, 2023 | In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2022-23506 | HIGH | 7.5 | 0.5% | Jan 3, 2023 | Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Ro... |
| CVE-2022-45867 | HIGH | 7.2 | 1.5% | Jan 3, 2023 | MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with hig... |
| CVE-2022-45143 | HIGH | 7.5 | 2.5% | Jan 3, 2023 | The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, mess... |
| CVE-2022-39947 | HIGH | 8.8 | 2.9% | Jan 3, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC versio... |
| CVE-2022-35845 | HIGH | 8.8 | 1.1% | Jan 3, 2023 | Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE... |
| CVE-2022-38766 | HIGH | 8.1 | 0.7% | Jan 3, 2023 | The remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for e... |
| CVE-2022-4871 | HIGH | 7.2 | 0.7% | Jan 3, 2023 | A vulnerability classified as problematic was found in ummmmm nflpick-em.com up to 2.2.x. This vulnerability affects the... |
| CVE-2022-47908 | HIGH | 7.8 | 0.3% | Jan 3, 2023 | Stack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the inform... |
| CVE-2022-47317 | HIGH | 7.8 | 0.2% | Jan 3, 2023 | Out-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information an... |
| CVE-2022-46360 | HIGH | 7.8 | 0.2% | Jan 3, 2023 | Out-of-bounds read vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now