2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-33639 | HIGH | 8.3 | 2.0% | Jun 29, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2022-33638 | HIGH | 8.3 | 1.9% | Jun 29, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2022-33042 | HIGH | 7.2 | 0.8% | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-30192 | HIGH | 8.3 | 2.1% | Jun 29, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2022-34043 | HIGH | 7.3 | 0.3% | Jun 29, 2022 | Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perf... |
| CVE-2022-33037 | HIGH | 7.8 | 0.4% | Jun 29, 2022 | A binary hijack in Orwell-Dev-Cpp v5.11 allows attackers to execute arbitrary code via a crafted .exe file. |
| CVE-2022-33036 | HIGH | 7.8 | 0.4% | Jun 29, 2022 | A binary hijack in Embarcadero Dev-CPP v6.3 allows attackers to execute arbitrary code via a crafted .exe file. |
| CVE-2022-33035 | HIGH | 7.8 | 0.4% | Jun 29, 2022 | XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes wi... |
| CVE-2022-33023 | HIGH | 7.5 | 0.6% | Jun 29, 2022 | CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wr... |
| CVE-2022-33021 | HIGH | 7.5 | 0.9% | Jun 29, 2022 | CVA6 commit 909d85a accesses invalid memory when reading the value of MHPMCOUNTER30. |
| CVE-2022-31883 | HIGH | 8.8 | 0.9% | Jun 28, 2022 | Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able ... |
| CVE-2022-2145 | HIGH | 7.8 | 0.3% | Jun 28, 2022 | Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder.... |
| CVE-2022-28621 | HIGH | 7.5 | 1.2% | Jun 28, 2022 | A remote disclosure of sensitive information vulnerability was discovered in HPE NonStop DSM/SCM version: T6031H03^ADP. ... |
| CVE-2022-33108 | HIGH | 7.8 | 1.1% | Jun 28, 2022 | XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files. |
| CVE-2022-30563 | HIGH | 7.4 | 0.9% | Jun 28, 2022 | When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in through ONVIF, he ... |
| CVE-2022-30560 | HIGH | 7.4 | 0.8% | Jun 28, 2022 | When an attacker obtaining the administrative account and password, or through a man-in-the-middle attack, the attacker ... |
| CVE-2022-23763 | HIGH | 8.8 | 0.3% | Jun 28, 2022 | Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files... |
| CVE-2022-34750 | HIGH | 7.5 | 1.2% | Jun 28, 2022 | An issue was discovered in MediaWiki through 1.38.1. The lemma length of a Wikibase lexeme is currently capped at a thou... |
| CVE-2022-30997 | HIGH | 7.2 | 1.4% | Jun 28, 2022 | Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which ma... |
| CVE-2022-30707 | HIGH | 8.8 | 0.6% | Jun 28, 2022 | Violation of secure design principles exists in the communication of CAMS for HIS. Affected products and versions are CE... |
| CVE-2022-29519 | HIGH | 7.5 | 0.4% | Jun 28, 2022 | Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 ... |
| CVE-2022-0624 | HIGH | 7.3 | 0.9% | Jun 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0. |
| CVE-2022-34134 | HIGH | 8.8 | 0.4% | Jun 28, 2022 | Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Use... |
| CVE-2022-31103 | HIGH | 7.5 | 1.4% | Jun 27, 2022 | lettersanitizer is a DOM-based HTML email sanitizer for in-browser email rendering. All versions of lettersanitizer belo... |
| CVE-2022-31101 | HIGH | 8.8 | 24.1% | Jun 27, 2022 | prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected v... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now