2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24893 | HIGH | 8.8 | 0.5% | Jun 25, 2022 | ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a ... |
| CVE-2022-33121 | HIGH | 8.1 | 0.4% | Jun 24, 2022 | A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clickin... |
| CVE-2022-22390 | HIGH | 7.5 | 0.9% | Jun 24, 2022 | IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure cause... |
| CVE-2022-20829 | HIGH | 7.2 | 3.2% | Jun 24, 2022 | A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those ima... |
| CVE-2022-20828 | HIGH | 7.2 | 39.9% | Jun 24, 2022 | A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module cou... |
| CVE-2022-2102 | HIGH | 7.5 | 0.8% | Jun 24, 2022 | Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the init... |
| CVE-2022-28619 | HIGH | 7.8 | 0.2% | Jun 24, 2022 | A potential security vulnerability has been identified in the installer of HPE Version Control Repository Manager. The v... |
| CVE-2022-1746 | HIGH | 7.6 | 0.3% | Jun 24, 2022 | The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Syste... |
| CVE-2022-1667 | HIGH | 7.5 | 1.2% | Jun 24, 2022 | Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the brow... |
| CVE-2022-32530 | HIGH | 7.8 | 0.4% | Jun 24, 2022 | A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, ... |
| CVE-2022-32143 | HIGH | 8.8 | 1.1% | Jun 24, 2022 | In multiple CODESYS products, file download and upload function allows access to internal files in the working directory... |
| CVE-2022-32142 | HIGH | 8.1 | 1.0% | Jun 24, 2022 | Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft ... |
| CVE-2022-32138 | HIGH | 8.8 | 1.1% | Jun 24, 2022 | In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, result... |
| CVE-2022-32137 | HIGH | 8.8 | 1.3% | Jun 24, 2022 | In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer ... |
| CVE-2022-31805 | HIGH | 7.5 | 1.0% | Jun 24, 2022 | In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication ... |
| CVE-2022-31804 | HIGH | 7.5 | 1.0% | Jun 24, 2022 | The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated ... |
| CVE-2022-1965 | HIGH | 8.1 | 1.0% | Jun 24, 2022 | Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, w... |
| CVE-2022-32405 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32404 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32403 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32402 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32401 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32400 | HIGH | 7.2 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32399 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32398 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now