2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31515 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The Delor4/CarceresBE repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file functi... |
| CVE-2022-31514 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The Caoyongqi912/Fan_Platform repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask s... |
| CVE-2022-31513 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The BolunHan/Krypton repository through 2021-06-03 on GitHub allows absolute path traversal because the Flask send_file ... |
| CVE-2022-31512 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file ... |
| CVE-2022-31511 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The AFDudley/equanimity repository through 2014-04-23 on GitHub allows absolute path traversal because the Flask send_fi... |
| CVE-2022-31510 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The sergeKashkin/Simple-RAT repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send... |
| CVE-2022-31509 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The iedadata/usap-dc-website repository through 1.0.1 on GitHub allows absolute path traversal because the Flask send_fi... |
| CVE-2022-31508 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The idayrus/evoting repository before 2022-05-08 on GitHub allows absolute path traversal because the Flask send_file fu... |
| CVE-2022-31507 | CRITICAL | 9.3 | 1.3% | Jul 11, 2022 | The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file funct... |
| CVE-2022-31506 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_fi... |
| CVE-2022-31505 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask se... |
| CVE-2022-31504 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because ... |
| CVE-2022-31503 | CRITICAL | 9.3 | 1.3% | Jul 11, 2022 | The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file fun... |
| CVE-2022-31502 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_fil... |
| CVE-2022-31501 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_f... |
| CVE-2022-31137 | CRITICAL | 9.8 | 90.4% | Jul 8, 2022 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are sub... |
| CVE-2022-35411 | CRITICAL | 9.8 | 45.9% | Jul 8, 2022 | rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i... |
| CVE-2022-34914 | CRITICAL | 9.8 | 0.9% | Jul 8, 2022 | Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in t... |
| CVE-2022-28623 | CRITICAL | 9.8 | 0.8% | Jul 8, 2022 | Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorize... |
| CVE-2022-1245 | CRITICAL | 9.8 | 1.0% | Jul 8, 2022 | A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client a... |
| CVE-2022-33936 | CRITICAL | 9.8 | 0.9% | Jul 7, 2022 | Cloud Mobility for Dell EMC Storage, 1.3.0.XXX contains a RCE vulnerability. A non-privileged user could potentially exp... |
| CVE-2022-34592 | CRITICAL | 9.8 | 3.5% | Jul 7, 2022 | Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obt... |
| CVE-2022-32449 | CRITICAL | 9.8 | 18.4% | Jul 7, 2022 | TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in... |
| CVE-2022-32056 | CRITICAL | 9.8 | 1.0% | Jul 7, 2022 | Online Accreditation Management v1.0 was discovered to contain a SQL injection vulnerability via the USERNAME parameter ... |
| CVE-2022-32054 | CRITICAL | 9.8 | 31.2% | Jul 7, 2022 | Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now