2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30260 | HIGH | 7.8 | 0.1% | Dec 26, 2022 | Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate check... |
| CVE-2022-26964 | HIGH | 7.5 | 0.5% | Dec 26, 2022 | Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure vi... |
| CVE-2022-41318 | HIGH | 8.6 | 2.8% | Dec 25, 2022 | A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection,... |
| CVE-2022-40005 | HIGH | 8.8 | 34.8% | Dec 25, 2022 | Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the... |
| CVE-2022-37706 | HIGH | 7.8 | 5.5% | Dec 25, 2022 | enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th... |
| CVE-2022-42898 | HIGH | 8.8 | 6.4% | Dec 25, 2022 | PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to r... |
| CVE-2022-45893 | HIGH | 8.8 | 0.8% | Dec 25, 2022 | Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user ... |
| CVE-2022-45197 | HIGH | 7.5 | 0.5% | Dec 25, 2022 | Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server ... |
| CVE-2022-44017 | HIGH | 7.5 | 0.7% | Dec 25, 2022 | An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can l... |
| CVE-2022-44016 | HIGH | 7.5 | 0.9% | Dec 25, 2022 | An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web ... |
| CVE-2022-42953 | HIGH | 7.5 | 4.8% | Dec 25, 2022 | Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct r... |
| CVE-2022-45889 | HIGH | 7.2 | 1.3% | Dec 25, 2022 | Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records ... |
| CVE-2022-46175 | HIGH | 8.8 | 9.3% | Dec 24, 2022 | JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for con... |
| CVE-2022-45798 | HIGH | 7.8 | 0.3% | Dec 24, 2022 | A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One a... |
| CVE-2022-38658 | HIGH | 7.5 | 0.3% | Dec 24, 2022 | BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix ope... |
| CVE-2022-47633 | HIGH | 8.1 | 1.0% | Dec 23, 2022 | An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a ma... |
| CVE-2022-28229 | HIGH | 7.5 | 0.7% | Dec 23, 2022 | The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of ... |
| CVE-2022-23854 | HIGH | 7.5 | 46.0% | Dec 23, 2022 | AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an ... |
| CVE-2022-41290 | HIGH | 8.4 | 0.2% | Dec 23, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache... |
| CVE-2022-46570 | HIGH | 7.2 | 1.4% | Dec 23, 2022 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password ... |
| CVE-2022-46569 | HIGH | 7.2 | 1.6% | Dec 23, 2022 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Key param... |
| CVE-2022-46568 | HIGH | 7.2 | 1.4% | Dec 23, 2022 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the AccountPa... |
| CVE-2022-46566 | HIGH | 7.2 | 1.4% | Dec 23, 2022 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password ... |
| CVE-2022-46563 | HIGH | 7.2 | 1.4% | Dec 23, 2022 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password ... |
| CVE-2022-46562 | HIGH | 7.2 | 1.4% | Dec 23, 2022 | D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the PSK param... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now