2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2185 | HIGH | 8.8 | 76.9% | Jul 1, 2022 | A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to... |
| CVE-2022-33103 | HIGH | 7.8 | 0.4% | Jul 1, 2022 | Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir(... |
| CVE-2022-33099 | HIGH | 7.5 | 2.1% | Jul 1, 2022 | An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error o... |
| CVE-2022-2264 | HIGH | 7.8 | 1.0% | Jul 1, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0. |
| CVE-2022-27904 | HIGH | 7 | 0.2% | Jul 1, 2022 | Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack d... |
| CVE-2022-33087 | HIGH | 7.5 | 1.4% | Jun 30, 2022 | A stack overflow in the function DM_ In fillobjbystr() of TP-Link Archer C50&A5(US)_V5_200407 allows attackers to cause ... |
| CVE-2022-33085 | HIGH | 7.2 | 1.5% | Jun 30, 2022 | ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename fu... |
| CVE-2022-33082 | HIGH | 7.5 | 1.4% | Jun 30, 2022 | An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (... |
| CVE-2022-31115 | HIGH | 8.8 | 1.3% | Jun 30, 2022 | opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML... |
| CVE-2022-2257 | HIGH | 7.8 | 1.1% | Jun 30, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. |
| CVE-2022-23720 | HIGH | 8.2 | 0.2% | Jun 30, 2022 | PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions ... |
| CVE-2022-23718 | HIGH | 8.1 | 1.6% | Jun 30, 2022 | PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker c... |
| CVE-2022-34793 | HIGH | 8.8 | 0.8% | Jun 30, 2022 | Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2022-34792 | HIGH | 8 | 0.4% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an H... |
| CVE-2022-31112 | HIGH | 8.2 | 1.0% | Jun 30, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected vers... |
| CVE-2022-22474 | HIGH | 7.5 | 0.9% | Jun 30, 2022 | IBM Spectrum Protect 8.1.0.0 through 8.1.14.0 dsmcad, dsmc, and dsmcsvc processes incorrectly handle certain read operat... |
| CVE-2022-22472 | HIGH | 8.8 | 0.7% | Jun 30, 2022 | IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.... |
| CVE-2022-33061 | HIGH | 7.2 | 0.7% | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-33060 | HIGH | 7.2 | 0.8% | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-33059 | HIGH | 7.2 | 0.8% | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-33058 | HIGH | 7.2 | 0.8% | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-33057 | HIGH | 7.2 | 0.8% | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-2073 | HIGH | 7.2 | 9.0% | Jun 29, 2022 | Code Injection in GitHub repository getgrav/grav prior to 1.7.34. |
| CVE-2022-31110 | HIGH | 7.5 | 1.2% | Jun 29, 2022 | RSSHub is an open source, extensible RSS feed generator. In commits prior to 5c4177441417 passing some special values to... |
| CVE-2022-31058 | HIGH | 7.2 | 1.1% | Jun 29, 2022 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now