2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27466 | CRITICAL | 9.8 | 1.6% | May 2, 2022 | MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do. |
| CVE-2022-28571 | CRITICAL | 9.8 | 5.6% | May 2, 2022 | D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli. |
| CVE-2022-1300 | CRITICAL | 9.8 | 1.4% | May 2, 2022 | Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of thi... |
| CVE-2022-25301 | CRITICAL | 9.8 | 1.2% | May 1, 2022 | All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attribute... |
| CVE-2022-25842 | CRITICAL | 9.8 | 3.6% | May 1, 2022 | All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Ex... |
| CVE-2022-25767 | CRITICAL | 9.8 | 2.9% | May 1, 2022 | All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a ma... |
| CVE-2022-24437 | CRITICAL | 9.8 | 3.9% | May 1, 2022 | The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack featu... |
| CVE-2022-23923 | CRITICAL | 9.8 | 1.3% | May 1, 2022 | All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main... |
| CVE-2022-22143 | CRITICAL | 9.8 | 2.0% | May 1, 2022 | The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validatio... |
| CVE-2022-21189 | CRITICAL | 9.8 | 1.9% | May 1, 2022 | The package dexie before 3.2.2, from 4.0.0-alpha.1 and before 4.0.0-alpha.3 are vulnerable to Prototype Pollution in the... |
| CVE-2022-21167 | CRITICAL | 9.8 | 1.3% | May 1, 2022 | All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function ... |
| CVE-2022-28481 | CRITICAL | 9.8 | 1.7% | May 1, 2022 | CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection. |
| CVE-2022-28994 | CRITICAL | 9.8 | 2.2% | Apr 29, 2022 | Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request. |
| CVE-2022-28480 | CRITICAL | 9.8 | 1.7% | Apr 29, 2022 | ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe. |
| CVE-2022-28452 | CRITICAL | 9.8 | 17.3% | Apr 29, 2022 | Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. |
| CVE-2022-1531 | CRITICAL | 9.8 | 3.5% | Apr 29, 2022 | SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint... |
| CVE-2022-29906 | CRITICAL | 9.8 | 1.2% | Apr 29, 2022 | The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf... |
| CVE-2022-29904 | CRITICAL | 9.8 | 16.3% | Apr 29, 2022 | The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQ... |
| CVE-2022-24449 | CRITICAL | 9.8 | 1.9% | Apr 28, 2022 | Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML doc... |
| CVE-2022-29556 | CRITICAL | 9.8 | 1.0% | Apr 28, 2022 | The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub... |
| CVE-2022-29081 | CRITICAL | 9.8 | 83.3% | Apr 28, 2022 | Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnera... |
| CVE-2022-29411 | CRITICAL | 9.8 | 1.0% | Apr 28, 2022 | SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers to execute SQL... |
| CVE-2022-28114 | CRITICAL | 9.1 | 1.0% | Apr 28, 2022 | DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php. |
| CVE-2022-28101 | CRITICAL | 9 | 1.0% | Apr 28, 2022 | Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML... |
| CVE-2022-28719 | CRITICAL | 9.8 | 4.3% | Apr 28, 2022 | Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker w... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now