2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34913 | CRITICAL | 9.8 | 2.0% | Jul 2, 2022 | md2roff 1.7 has a stack-based buffer overflow via a Markdown file containing a large number of consecutive characters to... |
| CVE-2022-32324 | CRITICAL | 9.8 | 1.0% | Jul 1, 2022 | PDFAlto v0.4 was discovered to contain a heap buffer overflow via the component /pdfalto/src/pdfalto.cc. |
| CVE-2022-32095 | CRITICAL | 9.8 | 1.3% | Jul 1, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orde... |
| CVE-2022-32094 | CRITICAL | 9.8 | 6.3% | Jul 1, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doc... |
| CVE-2022-32093 | CRITICAL | 9.8 | 1.3% | Jul 1, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adm... |
| CVE-2022-31943 | CRITICAL | 9.8 | 1.2% | Jul 1, 2022 | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability. |
| CVE-2022-25900 | CRITICAL | 9.8 | 3.2% | Jul 1, 2022 | All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature... |
| CVE-2022-25898 | CRITICAL | 9.8 | 0.9% | Jul 1, 2022 | The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT ... |
| CVE-2022-32032 | CRITICAL | 9.8 | 9.2% | Jul 1, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the function formAddMac... |
| CVE-2022-31605 | CRITICAL | 9.8 | 1.7% | Jul 1, 2022 | NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.loa... |
| CVE-2022-31604 | CRITICAL | 9.8 | 1.7% | Jul 1, 2022 | NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials ar... |
| CVE-2022-2253 | CRITICAL | 9.1 | 1.0% | Jul 1, 2022 | A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 may send OS commands to execute on t... |
| CVE-2022-2274 | CRITICAL | 9.8 | 36.5% | Jul 1, 2022 | The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA i... |
| CVE-2022-32295 | CRITICAL | 9.8 | 1.1% | Jul 1, 2022 | On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access... |
| CVE-2022-33329 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.... |
| CVE-2022-33328 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.... |
| CVE-2022-33327 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.... |
| CVE-2022-33326 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.... |
| CVE-2022-33325 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.... |
| CVE-2022-33314 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.... |
| CVE-2022-33313 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.... |
| CVE-2022-33312 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.... |
| CVE-2022-32585 | CRITICAL | 9.8 | 2.5% | Jun 30, 2022 | A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted ne... |
| CVE-2022-2197 | CRITICAL | 9.8 | 1.3% | Jun 30, 2022 | By using a specific credential string, an attacker with network access to the device’s web interface could circumvent th... |
| CVE-2022-28127 | CRITICAL | 9.1 | 34.6% | Jun 30, 2022 | A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A speci... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now