2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46306 | HIGH | 7.8 | 0.9% | Jan 3, 2023 | ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters ... |
| CVE-2022-46304 | HIGH | 8.8 | 1.5% | Jan 3, 2023 | ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. ... |
| CVE-2022-43448 | HIGH | 7.8 | 0.2% | Jan 3, 2023 | Out-of-bounds write vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker... |
| CVE-2022-43438 | HIGH | 8.8 | 0.8% | Jan 3, 2023 | The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as ... |
| CVE-2022-43437 | HIGH | 8.8 | 0.9% | Jan 3, 2023 | The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticate... |
| CVE-2022-43436 | HIGH | 8.8 | 0.9% | Jan 3, 2023 | The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker ... |
| CVE-2022-41645 | HIGH | 7.8 | 0.2% | Jan 3, 2023 | Out-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and... |
| CVE-2022-40740 | HIGH | 7.2 | 1.5% | Jan 3, 2023 | Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrat... |
| CVE-2022-39040 | HIGH | 7.5 | 1.7% | Jan 3, 2023 | aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this ... |
| CVE-2022-3460 | HIGH | 7.5 | 0.6% | Jan 3, 2023 | In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become u... |
| CVE-2022-3842 | HIGH | 7.5 | 18.3% | Jan 2, 2023 | Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the r... |
| CVE-2022-2743 | HIGH | 8.8 | 0.5% | Jan 2, 2023 | Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote atta... |
| CVE-2022-2742 | HIGH | 8.8 | 0.4% | Jan 2, 2023 | Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker wh... |
| CVE-2022-4373 | HIGH | 7.2 | 0.9% | Jan 2, 2023 | The Quote-O-Matic WordPress plugin through 1.0.5 does not properly sanitize and escape a parameter before using it in a ... |
| CVE-2022-4372 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQ... |
| CVE-2022-4371 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQ... |
| CVE-2022-4370 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The multimedial images WordPress plugin through 1.0b does not properly sanitize and escape a parameter before using it i... |
| CVE-2022-4360 | HIGH | 7.2 | 1.1% | Jan 2, 2023 | The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it ... |
| CVE-2022-4359 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it ... |
| CVE-2022-4358 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it ... |
| CVE-2022-4356 | HIGH | 7.2 | 0.9% | Jan 2, 2023 | The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2022-4355 | HIGH | 7.2 | 0.9% | Jan 2, 2023 | The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2022-4352 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a ... |
| CVE-2022-4351 | HIGH | 7.2 | 1.1% | Jan 2, 2023 | The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a ... |
| CVE-2022-4324 | HIGH | 7.2 | 17.7% | Jan 2, 2023 | The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now