2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22487 | CRITICAL | 9.8 | 1.3% | Jun 30, 2022 | An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimite... |
| CVE-2022-34835 | CRITICAL | 9.8 | 1.7% | Jun 30, 2022 | In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md"... |
| CVE-2022-33107 | CRITICAL | 9.8 | 21.9% | Jun 29, 2022 | ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cac... |
| CVE-2022-32532 | CRITICAL | 9.8 | 25.4% | Jun 29, 2022 | Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applica... |
| CVE-2022-31887 | CRITICAL | 9.8 | 1.5% | Jun 28, 2022 | Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's pas... |
| CVE-2022-31885 | CRITICAL | 9.8 | 31.3% | Jun 28, 2022 | Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. |
| CVE-2022-31230 | CRITICAL | 9.8 | 0.6% | Jun 28, 2022 | Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain broken or risky cryptographic algorithm. A remote unprivileged mali... |
| CVE-2022-31106 | CRITICAL | 9.8 | 1.0% | Jun 28, 2022 | Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of `underscore.deep` prior... |
| CVE-2022-31061 | CRITICAL | 9.8 | 51.2% | Jun 28, 2022 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an... |
| CVE-2022-31056 | CRITICAL | 9.8 | 8.6% | Jun 28, 2022 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an... |
| CVE-2022-34132 | CRITICAL | 9.8 | 1.5% | Jun 28, 2022 | Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leav... |
| CVE-2022-32995 | CRITICAL | 9.8 | 15.9% | Jun 27, 2022 | Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function... |
| CVE-2022-32994 | CRITICAL | 9.8 | 16.7% | Jun 27, 2022 | Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachment... |
| CVE-2022-32092 | CRITICAL | 9.8 | 5.6% | Jun 27, 2022 | D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __aja... |
| CVE-2022-31082 | CRITICAL | 9.8 | 0.9% | Jun 27, 2022 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an... |
| CVE-2022-28171 | CRITICAL | 9.8 | 49.9% | Jun 27, 2022 | The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t... |
| CVE-2022-2140 | CRITICAL | 9 | 0.8% | Jun 27, 2022 | Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject ar... |
| CVE-2022-2216 | CRITICAL | 9.8 | 1.5% | Jun 27, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0. |
| CVE-2022-1953 | CRITICAL | 9.1 | 1.7% | Jun 27, 2022 | The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerab... |
| CVE-2022-1574 | CRITICAL | 9.8 | 11.9% | Jun 27, 2022 | The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does no... |
| CVE-2022-33128 | CRITICAL | 9.1 | 0.8% | Jun 25, 2022 | RG-EG series gateway EG350 EG_RGOS 11.1(6) was discovered to contain a SQL injection vulnerability via the function get_... |
| CVE-2022-34066 | CRITICAL | 9.8 | 2.0% | Jun 24, 2022 | The Texercise package in PyPI v0.0.1 to v0.0.12 was discovered to contain a code execution backdoor. This vulnerability ... |
| CVE-2022-34065 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Rondolu-YT-Concate package in PyPI v0.1.0 was discovered to contain a code execution backdoor. This vulnerability al... |
| CVE-2022-34064 | CRITICAL | 9.8 | 1.3% | Jun 24, 2022 | The Zibal package in PyPI v1.0.0 was discovered to contain a code execution backdoor. This vulnerability allows attacker... |
| CVE-2022-34061 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Catly-Translate package in PyPI v0.0.3 to v0.0.5 was discovered to contain a code execution backdoor. This vulnerabi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now