2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4809 | HIGH | 8.8 | 0.9% | Dec 28, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4808 | HIGH | 8.8 | 0.4% | Dec 28, 2022 | Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4803 | HIGH | 8.8 | 0.8% | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4796 | HIGH | 8.1 | 0.8% | Dec 28, 2022 | Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-46179 | HIGH | 7.8 | 0.3% | Dec 28, 2022 | LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of... |
| CVE-2022-3347 | HIGH | 7.5 | 0.2% | Dec 28, 2022 | DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for inv... |
| CVE-2022-23555 | HIGH | 8.8 | 0.9% | Dec 28, 2022 | authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 20... |
| CVE-2022-41967 | HIGH | 7.5 | 0.6% | Dec 28, 2022 | Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderF... |
| CVE-2022-41966 | HIGH | 7.5 | 8.7% | Dec 28, 2022 | XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate... |
| CVE-2022-4772 | HIGH | 7.8 | 0.3% | Dec 27, 2022 | A vulnerability was found in Widoco and classified as critical. Affected by this issue is the function unZipIt of the fi... |
| CVE-2022-3064 | HIGH | 7.5 | 1.7% | Dec 27, 2022 | Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory. |
| CVE-2022-2584 | HIGH | 7.5 | 0.7% | Dec 27, 2022 | The dag-pb codec can panic when decoding invalid blocks. |
| CVE-2022-3156 | HIGH | 7.8 | 0.4% | Dec 27, 2022 | A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. Users are grant... |
| CVE-2022-45431 | HIGH | 7.5 | 0.6% | Dec 27, 2022 | Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the f... |
| CVE-2022-45429 | HIGH | 7.5 | 0.5% | Dec 27, 2022 | Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal... |
| CVE-2022-45427 | HIGH | 7.2 | 0.7% | Dec 27, 2022 | Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of adm... |
| CVE-2022-45425 | HIGH | 7.5 | 0.5% | Dec 27, 2022 | Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the A... |
| CVE-2022-45423 | HIGH | 7.5 | 0.6% | Dec 27, 2022 | Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain... |
| CVE-2022-4767 | HIGH | 7.5 | 0.7% | Dec 27, 2022 | Denial of Service in GitHub repository usememos/memos prior to 0.9.1. |
| CVE-2022-4732 | HIGH | 7.2 | 38.2% | Dec 27, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. |
| CVE-2022-4722 | HIGH | 7.2 | 1.1% | Dec 27, 2022 | Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5. |
| CVE-2022-46763 | HIGH | 8.8 | 1.1% | Dec 27, 2022 | A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-p... |
| CVE-2022-4268 | HIGH | 7.2 | 1.1% | Dec 26, 2022 | The Plugin Logic WordPress plugin before 1.0.8 does not sanitise and escape a parameter before using it in a SQL stateme... |
| CVE-2022-4158 | HIGH | 7.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4156 | HIGH | 7.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now