2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24690 | HIGH | 8.2 | 1.0% | Jul 18, 2022 | An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauth... |
| CVE-2022-24688 | HIGH | 8.8 | 2.7% | Jul 18, 2022 | An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and ... |
| CVE-2022-36127 | HIGH | 7.5 | 1.6% | Jul 18, 2022 | A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has ... |
| CVE-2022-33891 | HIGH | 8.8 | 93.0% | Jul 18, 2022 | The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authen... |
| CVE-2022-33903 | HIGH | 7.5 | 1.1% | Jul 17, 2022 | Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation. |
| CVE-2022-31213 | HIGH | 7.5 | 1.7% | Jul 17, 2022 | An issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malfo... |
| CVE-2022-31212 | HIGH | 7.5 | 1.7% | Jul 17, 2022 | An issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. ... |
| CVE-2022-31208 | HIGH | 8.8 | 1.3% | Jul 17, 2022 | An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary comm... |
| CVE-2022-30981 | HIGH | 8.8 | 1.1% | Jul 17, 2022 | An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserial... |
| CVE-2022-28809 | HIGH | 7.8 | 0.4% | Jul 17, 2022 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists w... |
| CVE-2022-28808 | HIGH | 7.8 | 0.4% | Jul 17, 2022 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists w... |
| CVE-2022-28807 | HIGH | 7.8 | 0.4% | Jul 17, 2022 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.2. An Out-of-Bounds Read vulnerability exists w... |
| CVE-2022-26482 | HIGH | 7.2 | 22.3% | Jul 17, 2022 | An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an a... |
| CVE-2022-26481 | HIGH | 8.8 | 1.6% | Jul 17, 2022 | An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificat... |
| CVE-2022-32263 | HIGH | 7.5 | 0.9% | Jul 17, 2022 | Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719. |
| CVE-2022-29286 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because ... |
| CVE-2022-30622 | HIGH | 7.3 | 0.2% | Jul 17, 2022 | Disclosure of information - the system allows you to view usernames and passwords without permissions, thus it will be p... |
| CVE-2022-27937 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264. |
| CVE-2022-27936 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323. |
| CVE-2022-27935 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth. |
| CVE-2022-27934 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via HTTP. |
| CVE-2022-27933 | HIGH | 8.2 | 0.9% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join. |
| CVE-2022-27932 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join. |
| CVE-2022-27931 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol. |
| CVE-2022-27929 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via HTTP. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now