2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27668 | CRITICAL | 9.8 | 2.0% | Jun 14, 2022 | Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated... |
| CVE-2022-32352 | CRITICAL | 9.8 | 1.0% | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_... |
| CVE-2022-32328 | CRITICAL | 9.1 | 1.1% | Jun 14, 2022 | Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img. |
| CVE-2022-32336 | CRITICAL | 9.8 | 1.0% | Jun 14, 2022 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=. |
| CVE-2022-31311 | CRITICAL | 9.8 | 2.8% | Jun 14, 2022 | An issue in adm.cgi of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to execute arbitrary commands via a cr... |
| CVE-2022-27889 | CRITICAL | 9.1 | 0.9% | Jun 14, 2022 | The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication ... |
| CVE-2022-31273 | CRITICAL | 9.8 | 0.9% | Jun 14, 2022 | An issue in TopIDP3000 Topsec Operating System tos_3.3.005.665b.15_smpidp allows attackers to perform a brute-force atta... |
| CVE-2022-32262 | CRITICAL | 9.8 | 2.4% | Jun 14, 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application cont... |
| CVE-2022-32260 | CRITICAL | 9.8 | 0.7% | Jun 14, 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application ... |
| CVE-2022-32251 | CRITICAL | 9.8 | 1.1% | Jun 14, 2022 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentica... |
| CVE-2022-30230 | CRITICAL | 9.8 | 1.0% | Jun 14, 2022 | A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does n... |
| CVE-2022-25651 | CRITICAL | 9.8 | 0.8% | Jun 14, 2022 | Memory corruption in bluetooth host due to integer overflow while processing BT HFP-UNIT profile in Snapdragon Auto, Sna... |
| CVE-2022-22087 | CRITICAL | 9.8 | 0.5% | Jun 14, 2022 | memory corruption in video due to buffer overflow while parsing mkv clip with no codechecker in Snapdragon Auto, Snapdra... |
| CVE-2022-22086 | CRITICAL | 9.8 | 0.5% | Jun 14, 2022 | Memory corruption in video due to double free while parsing 3gp clip with invalid meta data atoms in Snapdragon Auto, Sn... |
| CVE-2022-25167 | CRITICAL | 9.8 | 4.6% | Jun 14, 2022 | Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration us... |
| CVE-2022-31446 | CRITICAL | 9.8 | 32.1% | Jun 14, 2022 | Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability vi... |
| CVE-2022-29247 | CRITICAL | 9.8 | 0.9% | Jun 13, 2022 | Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerab... |
| CVE-2022-31053 | CRITICAL | 9.8 | 1.0% | Jun 13, 2022 | Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version ... |
| CVE-2022-29797 | CRITICAL | 9.8 | 0.8% | Jun 13, 2022 | There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46. Successful exploitation of this vulnerability ma... |
| CVE-2022-33175 | CRITICAL | 9.8 | 1.7% | Jun 13, 2022 | Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions sett... |
| CVE-2022-23168 | CRITICAL | 9.8 | 0.4% | Jun 13, 2022 | The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: userna... |
| CVE-2022-23167 | CRITICAL | 9.8 | 0.4% | Jun 13, 2022 | Attacker crafts a GET request to: /mobile/downloadfile.aspx? Filename =../.. /windows/boot.ini the LFI is UNAUTHENTICATE... |
| CVE-2022-31760 | CRITICAL | 9.1 | 0.6% | Jun 13, 2022 | Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploit... |
| CVE-2022-30311 | CRITICAL | 9.8 | 2.8% | Jun 13, 2022 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST reque... |
| CVE-2022-30310 | CRITICAL | 9.8 | 2.5% | Jun 13, 2022 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST reque... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now