2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36234 | HIGH | 7.5 | 0.8% | Jul 28, 2022 | SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnera... |
| CVE-2022-34557 | HIGH | 8.8 | 0.8% | Jul 28, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /... |
| CVE-2022-34568 | HIGH | 7.5 | 0.9% | Jul 28, 2022 | SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c. |
| CVE-2022-30287 | HIGH | 8 | 70.3% | Jul 28, 2022 | Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instan... |
| CVE-2022-2399 | HIGH | 8.8 | 0.6% | Jul 28, 2022 | Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap c... |
| CVE-2022-29558 | HIGH | 8.8 | 1.2% | Jul 28, 2022 | Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface. |
| CVE-2022-34593 | HIGH | 7.5 | 0.6% | Jul 28, 2022 | DPTech VPN v8.1.28.0 was discovered to contain an arbitrary file read vulnerability. |
| CVE-2022-34578 | HIGH | 7.2 | 1.0% | Jul 28, 2022 | Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Brandin... |
| CVE-2022-30319 | HIGH | 8.1 | 0.6% | Jul 28, 2022 | Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. According to FSCT-2022-0062, there is a... |
| CVE-2022-30313 | HIGH | 7.5 | 0.7% | Jul 28, 2022 | Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According t... |
| CVE-2022-1805 | HIGH | 8.1 | 0.5% | Jul 28, 2022 | When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero C... |
| CVE-2022-37009 | HIGH | 7.8 | 0.2% | Jul 28, 2022 | In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible |
| CVE-2022-36364 | HIGH | 8.8 | 2.2% | Jul 28, 2022 | Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` con... |
| CVE-2022-27611 | HIGH | 8.1 | 0.9% | Jul 28, 2022 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno... |
| CVE-2022-27614 | HIGH | 7.5 | 0.8% | Jul 28, 2022 | Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1... |
| CVE-2022-27613 | HIGH | 8.8 | 0.9% | Jul 28, 2022 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component i... |
| CVE-2022-22685 | HIGH | 8.1 | 1.1% | Jul 28, 2022 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno... |
| CVE-2022-22684 | HIGH | 8.8 | 1.5% | Jul 28, 2022 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task managem... |
| CVE-2022-27615 | HIGH | 8.1 | 1.0% | Jul 28, 2022 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synolog... |
| CVE-2022-2481 | HIGH | 8.8 | 1.0% | Jul 28, 2022 | Use after free in Views in Google Chrome prior to 103.0.5060.134 allowed a remote attacker who convinced a user to engag... |
| CVE-2022-2480 | HIGH | 8.8 | 17.9% | Jul 28, 2022 | Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially e... |
| CVE-2022-2478 | HIGH | 8.8 | 0.8% | Jul 28, 2022 | Use after free in PDF in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2022-2477 | HIGH | 8.8 | 0.7% | Jul 28, 2022 | Use after free in Guest View in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to instal... |
| CVE-2022-2296 | HIGH | 8.8 | 0.9% | Jul 28, 2022 | Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who co... |
| CVE-2022-2295 | HIGH | 8.8 | 1.2% | Jul 28, 2022 | Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corr... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now