2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30309 | CRITICAL | 9.8 | 3.0% | Jun 13, 2022 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POS... |
| CVE-2022-30308 | CRITICAL | 9.8 | 2.7% | Jun 13, 2022 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST... |
| CVE-2022-2067 | CRITICAL | 9.1 | 1.8% | Jun 13, 2022 | SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0. |
| CVE-2022-0885 | CRITICAL | 9.8 | 9.1% | Jun 13, 2022 | The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter... |
| CVE-2022-0827 | CRITICAL | 9.8 | 9.0% | Jun 13, 2022 | The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL sta... |
| CVE-2022-0786 | CRITICAL | 9.8 | 11.2% | Jun 13, 2022 | The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL stateme... |
| CVE-2022-29525 | CRITICAL | 9.8 | 1.4% | Jun 13, 2022 | Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated at... |
| CVE-2022-29095 | CRITICAL | 9.6 | 1.1% | Jun 10, 2022 | Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 ... |
| CVE-2022-25863 | CRITICAL | 9.8 | 1.8% | Jun 10, 2022 | The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted... |
| CVE-2022-25845 | CRITICAL | 9.8 | 17.8% | Jun 10, 2022 | The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the defa... |
| CVE-2022-24376 | CRITICAL | 9.8 | 3.0% | Jun 10, 2022 | All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerab... |
| CVE-2022-24278 | CRITICAL | 9.8 | 2.0% | Jun 10, 2022 | The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags... |
| CVE-2022-31788 | CRITICAL | 9.8 | 13.9% | Jun 10, 2022 | IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname. |
| CVE-2022-32563 | CRITICAL | 9.8 | 0.7% | Jun 10, 2022 | An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 ... |
| CVE-2022-31045 | CRITICAL | 9.8 | 1.0% | Jun 9, 2022 | Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to ... |
| CVE-2022-29226 | CRITICAL | 9.1 | 1.2% | Jun 9, 2022 | Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not inc... |
| CVE-2022-31813 | CRITICAL | 9.8 | 3.1% | Jun 9, 2022 | Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side C... |
| CVE-2022-28615 | CRITICAL | 9.1 | 5.7% | Jun 9, 2022 | Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match()... |
| CVE-2022-1992 | CRITICAL | 9.1 | 2.3% | Jun 9, 2022 | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. |
| CVE-2022-1986 | CRITICAL | 9.8 | 4.5% | Jun 9, 2022 | OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9. |
| CVE-2022-31031 | CRITICAL | 9.8 | 1.8% | Jun 9, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2022-32272 | CRITICAL | 9.8 | 8.9% | Jun 9, 2022 | OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5... |
| CVE-2022-31830 | CRITICAL | 9.1 | 14.6% | Jun 9, 2022 | Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.... |
| CVE-2022-31827 | CRITICAL | 9.1 | 19.1% | Jun 9, 2022 | MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at... |
| CVE-2022-31393 | CRITICAL | 9.1 | 1.0% | Jun 9, 2022 | Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now