Skip to main content

Year archive

CVEs published in 2022

Archive summary

25,074 CVEs published in 2022 — 3,757 Critical, 9,686 High, 10,678 Medium, 949 Low, 4 Unrated.

CVE-2015-10004

Published Dec 27, 2022

Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-125026

Published Dec 27, 2022

LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-10005

Published Dec 27, 2022

The RemoteAddr and LocalAddr methods on the returned net.Conn may call themselves, leading to an infinite loop which will crash the program due to a stack overflow.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36567

Published Dec 27, 2022

Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3156

Published Dec 27, 2022

A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when th…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-47968

Published Dec 27, 2022

Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Applica…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45434

Published Dec 27, 2022

Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sendin…

CVSS 5.9 · Medium

CVE-2022-45433

Published Dec 27, 2022

Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a speci…

CVSS 3.7 · Low

CVE-2022-45432

Published Dec 27, 2022

Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet t…

CVSS 5.3 · Medium

CVE-2022-45431

Published Dec 27, 2022

Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafte…

CVSS 7.5 · High

CVE-2022-45430

Published Dec 27, 2022

Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific craf…

CVSS 3.7 · Low

CVE-2022-45429

Published Dec 27, 2022

Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating links (URL) that conform to spe…

CVSS 7.5 · High

CVE-2022-45428

Published Dec 27, 2022

Some Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of administrators, by sending a specific crafted packet to the…

CVSS 2.7 · Low

CVE-2022-45427

Published Dec 27, 2022

Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vu…

CVSS 7.2 · High

CVE-2022-45426

Published Dec 27, 2022

Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of ordinary users, by sending a specific crafted packet to the…

CVSS 6.5 · Medium

CVE-2022-45425

Published Dec 27, 2022

Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability.

CVSS 7.5 · High

CVE-2022-45424

Published Dec 27, 2022

Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending a specific crafted packet to t…

CVSS 5.3 · Medium

CVE-2022-45423

Published Dec 27, 2022

Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted p…

CVSS 7.5 · High

CVE-2022-4767

Published Dec 27, 2022

Denial of Service in GitHub repository usememos/memos prior to 0.9.1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4734

Published Dec 27, 2022

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4733

Published Dec 27, 2022

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4732

Published Dec 27, 2022

Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4730

Published Dec 27, 2022

A vulnerability was found in Graphite Web. It has been classified as problematic. Affected is an unknown function of the component Absolute Time Range Handler. The manipulation le…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-4729

Published Dec 27, 2022

A vulnerability was found in Graphite Web and classified as problematic. This issue affects some unknown processing of the component Template Name Handler. The manipulation leads…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-4728

Published Dec 27, 2022

A vulnerability has been found in Graphite Web and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to cr…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 226-250 of 25,074 CVEsPage 10 of 1003