2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32397 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32396 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32395 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32394 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32393 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32392 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-32391 | HIGH | 8.8 | 1.2% | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm... |
| CVE-2022-2147 | HIGH | 7.8 | 0.3% | Jun 23, 2022 | Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code exe... |
| CVE-2022-2183 | HIGH | 7.8 | 1.5% | Jun 23, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-2182 | HIGH | 7.8 | 1.5% | Jun 23, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-26864 | HIGH | 7.8 | 0.3% | Jun 23, 2022 | Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potenti... |
| CVE-2022-26863 | HIGH | 7.8 | 0.3% | Jun 23, 2022 | Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potenti... |
| CVE-2022-26862 | HIGH | 7.8 | 0.3% | Jun 23, 2022 | Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potenti... |
| CVE-2022-34300 | HIGH | 8.8 | 1.4% | Jun 23, 2022 | In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData. |
| CVE-2022-34299 | HIGH | 8.1 | 1.1% | Jun 23, 2022 | There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b. |
| CVE-2022-34296 | HIGH | 7.5 | 1.1% | Jun 23, 2022 | In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request. |
| CVE-2022-34203 | HIGH | 8.8 | 0.5% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect t... |
| CVE-2022-34200 | HIGH | 8.8 | 0.5% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows at... |
| CVE-2022-34180 | HIGH | 7.5 | 1.1% | Jun 23, 2022 | Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in t... |
| CVE-2022-34179 | HIGH | 7.5 | 1.6% | Jun 23, 2022 | Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to cho... |
| CVE-2022-34177 | HIGH | 7.5 | 1.5% | Jun 23, 2022 | Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for P... |
| CVE-2022-34175 | HIGH | 7.5 | 1.3% | Jun 23, 2022 | Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby di... |
| CVE-2022-34174 | HIGH | 7.5 | 1.2% | Jun 23, 2022 | In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows disting... |
| CVE-2022-33114 | HIGH | 7.2 | 0.9% | Jun 23, 2022 | Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/syste... |
| CVE-2022-33105 | HIGH | 7.5 | 3.0% | Jun 23, 2022 | Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now