2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26290 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/Writ... |
| CVE-2022-26289 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeC... |
| CVE-2022-25269 | MEDIUM | 6.1 | 0.5% | Mar 23, 2022 | Passwork On-Premise Edition before 4.6.13 has multiple XSS issues. |
| CVE-2022-25268 | HIGH | 8.8 | 0.4% | Mar 23, 2022 | Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems. |
| CVE-2022-25267 | HIGH | 8.8 | 1.4% | Mar 23, 2022 | Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files). |
| CVE-2022-25266 | MEDIUM | 4.3 | 0.9% | Mar 23, 2022 | Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files). |
| CVE-2022-27254 | MEDIUM | 5.3 | 1.1% | Mar 23, 2022 | The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows... |
| CVE-2022-27192 | HIGH | 7.5 | 1.1% | Mar 23, 2022 | The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file downl... |
| CVE-2022-25041 | MEDIUM | 4.3 | 0.8% | Mar 23, 2022 | OpenEMR v6.0.0 was discovered to contain an incorrect access control issue. |
| CVE-2022-24934 | CRITICAL | 9.8 | 20.5% | Mar 23, 2022 | wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER i... |
| CVE-2022-24768 | HIGH | 8.8 | 1.2% | Mar 23, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting wit... |
| CVE-2022-22819 | HIGH | 7.8 | 1.3% | Mar 23, 2022 | NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM... |
| CVE-2022-24757 | HIGH | 7.5 | 1.2% | Mar 23, 2022 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications.... |
| CVE-2022-24731 | MEDIUM | 4.9 | 0.9% | Mar 23, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before... |
| CVE-2022-24730 | MEDIUM | 6.5 | 0.9% | Mar 23, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before... |
| CVE-2022-23881 | CRITICAL | 9.8 | 56.5% | Mar 23, 2022 | ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_te... |
| CVE-2022-23880 | CRITICAL | 9.8 | 1.6% | Mar 23, 2022 | An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execu... |
| CVE-2022-25609 | MEDIUM | 5.4 | 0.5% | Mar 23, 2022 | Stored Cross-Site Scripting (XSS) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers with c... |
| CVE-2022-25608 | MEDIUM | 5.4 | 0.3% | Mar 23, 2022 | Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to tri... |
| CVE-2022-25223 | MEDIUM | 4.3 | 0.8% | Mar 23, 2022 | Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=tra... |
| CVE-2022-25222 | CRITICAL | 9.8 | 1.6% | Mar 23, 2022 | Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/... |
| CVE-2022-25221 | MEDIUM | 6.1 | 0.7% | Mar 23, 2022 | Money Transfer Management System Version 1.0 allows an attacker to inject JavaScript code in the URL and then trick a us... |
| CVE-2022-24293 | CRITICAL | 9.8 | 7.0% | Mar 23, 2022 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execut... |
| CVE-2022-24292 | CRITICAL | 9.8 | 7.0% | Mar 23, 2022 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execut... |
| CVE-2022-24291 | HIGH | 7.5 | 4.4% | Mar 23, 2022 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execut... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now