Skip to main content

Year archive

CVEs published in 2022

Archive summary

25,074 CVEs published in 2022 — 3,757 Critical, 9,685 High, 10,678 Medium, 950 Low, 4 Unrated.

CVE-2021-4283

Published Dec 27, 2022

A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file views/ssettings.php of the compo…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-4282

Published Dec 27, 2022

A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file page.voicemail.php. The…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-25088

Published Dec 27, 2022

A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The man…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-4748

Published Dec 27, 2022

A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanager/panels/panel.mediamanager.f…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25087

Published Dec 27, 2022

A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the c…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25086

Published Dec 27, 2022

A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/cont…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-25049

Published Dec 27, 2022

A vulnerability was found in email-existence. It has been rated as problematic. Affected by this issue is some unknown functionality of the file index.js. The manipulation leads t…

CVSS 3.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-10005

Published Dec 27, 2022

A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation lead…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-46764

Published Dec 27, 2022

A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately le…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-46763

Published Dec 27, 2022

A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19030

Published Dec 26, 2022

Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11851

Published Dec 26, 2022

The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary co…

CVSS 9.8 · Critical

CVE-2018-16135

Published Dec 26, 2022

The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14802

Published Dec 26, 2022

HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applie…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-4281

Published Dec 26, 2022

A vulnerability was found in Brave UX for-the-badge and classified as critical. Affected by this issue is some unknown functionality of the file .github/workflows/combine-prs.yml.…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11101

Published Dec 26, 2022

Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9011

Published Dec 26, 2022

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 25,074 CVEsPage 12 of 1003