2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1586 | CRITICAL | 9.1 | 3.0% | May 16, 2022 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of... |
| CVE-2022-23666 | CRITICAL | 9.1 | 2.1% | May 16, 2022 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10... |
| CVE-2022-23665 | CRITICAL | 9.1 | 2.1% | May 16, 2022 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10... |
| CVE-2022-23664 | CRITICAL | 9.1 | 2.1% | May 16, 2022 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10... |
| CVE-2022-23663 | CRITICAL | 9.1 | 2.1% | May 16, 2022 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10... |
| CVE-2022-23662 | CRITICAL | 9.1 | 2.1% | May 16, 2022 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10... |
| CVE-2022-23661 | CRITICAL | 9.1 | 2.1% | May 16, 2022 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10... |
| CVE-2022-23660 | CRITICAL | 10 | 2.6% | May 16, 2022 | A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and bel... |
| CVE-2022-23658 | CRITICAL | 10 | 2.6% | May 16, 2022 | A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and bel... |
| CVE-2022-23657 | CRITICAL | 10 | 2.9% | May 16, 2022 | A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and bel... |
| CVE-2022-1731 | CRITICAL | 9.8 | 1.2% | May 16, 2022 | Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO... |
| CVE-2022-30055 | CRITICAL | 9.8 | 3.7% | May 16, 2022 | Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution. |
| CVE-2022-1386 | CRITICAL | 9.8 | 71.7% | May 16, 2022 | The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms wh... |
| CVE-2022-0867 | CRITICAL | 9.8 | 11.3% | May 16, 2022 | The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it ... |
| CVE-2022-29622 | CRITICAL | 9.8 | 3.2% | May 16, 2022 | An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted fil... |
| CVE-2022-29354 | CRITICAL | 9.8 | 2.4% | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrar... |
| CVE-2022-29353 | CRITICAL | 9.8 | 1.6% | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute a... |
| CVE-2022-29351 | CRITICAL | 9.8 | 2.4% | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbit... |
| CVE-2022-30011 | CRITICAL | 9.8 | 18.5% | May 16, 2022 | In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability. |
| CVE-2022-30767 | CRITICAL | 9.8 | 2.4% | May 16, 2022 | nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a fai... |
| CVE-2022-30765 | CRITICAL | 9.8 | 1.1% | May 16, 2022 | Calibre-Web before 0.6.18 allows user table SQL Injection. |
| CVE-2022-28930 | CRITICAL | 9.8 | 1.0% | May 15, 2022 | ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper... |
| CVE-2022-28929 | CRITICAL | 9.8 | 1.6% | May 15, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewt... |
| CVE-2022-1379 | CRITICAL | 9.1 | 1.5% | May 14, 2022 | URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass U... |
| CVE-2022-24831 | CRITICAL | 9.8 | 1.0% | May 14, 2022 | OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions pr... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now