2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28620 | CRITICAL | 9.8 | 1.5% | Jun 24, 2022 | A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; a... |
| CVE-2022-23170 | CRITICAL | 9.8 | 0.6% | Jun 24, 2022 | SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection vulnerability. Any SysAid environm... |
| CVE-2022-21829 | CRITICAL | 9.8 | 1.7% | Jun 24, 2022 | Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from tho... |
| CVE-2022-1668 | CRITICAL | 9.8 | 2.0% | Jun 24, 2022 | Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP por... |
| CVE-2022-1521 | CRITICAL | 9.1 | 1.0% | Jun 24, 2022 | LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or ... |
| CVE-2022-1519 | CRITICAL | 9.8 | 1.3% | Jun 24, 2022 | LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any ... |
| CVE-2022-1518 | CRITICAL | 9.8 | 1.5% | Jun 24, 2022 | LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directo... |
| CVE-2022-1517 | CRITICAL | 9.8 | 1.6% | Jun 24, 2022 | LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operati... |
| CVE-2022-31806 | CRITICAL | 9.8 | 1.1% | Jun 24, 2022 | In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by defau... |
| CVE-2022-31802 | CRITICAL | 9.8 | 1.2% | Jun 24, 2022 | In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared ... |
| CVE-2022-34181 | CRITICAL | 9.1 | 1.2% | Jun 23, 2022 | Jenkins xUnit Plugin 3.0.8 and earlier implements an agent-to-controller message that creates a user-specified directory... |
| CVE-2022-33127 | CRITICAL | 9.8 | 1.7% | Jun 23, 2022 | The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a ... |
| CVE-2022-32554 | CRITICAL | 9.8 | 1.2% | Jun 23, 2022 | Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x ... |
| CVE-2022-32535 | CRITICAL | 9.8 | 0.7% | Jun 23, 2022 | The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combinati... |
| CVE-2022-32534 | CRITICAL | 9.8 | 2.3% | Jun 23, 2022 | The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command inj... |
| CVE-2022-31787 | CRITICAL | 9.8 | 1.4% | Jun 23, 2022 | IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO |
| CVE-2022-31361 | CRITICAL | 9.8 | 1.3% | Jun 23, 2022 | Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerabil... |
| CVE-2022-22980 | CRITICAL | 9.8 | 16.9% | Jun 23, 2022 | A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query meth... |
| CVE-2022-26147 | CRITICAL | 9.8 | 2.5% | Jun 21, 2022 | The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection. |
| CVE-2022-29775 | CRITICAL | 9.8 | 59.9% | Jun 21, 2022 | iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL. |
| CVE-2022-29774 | CRITICAL | 9.8 | 5.4% | Jun 21, 2022 | iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal. |
| CVE-2022-33139 | CRITICAL | 9.8 | 1.2% | Jun 21, 2022 | A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All ver... |
| CVE-2022-31374 | CRITICAL | 9.8 | 2.5% | Jun 21, 2022 | An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute ... |
| CVE-2022-31801 | CRITICAL | 9.8 | 1.0% | Jun 21, 2022 | An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order... |
| CVE-2022-31800 | CRITICAL | 9.8 | 1.5% | Jun 21, 2022 | An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now