2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32992 | HIGH | 7.2 | 0.9% | Jun 15, 2022 | Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the tname pa... |
| CVE-2022-32991 | HIGH | 8.8 | 1.0% | Jun 15, 2022 | Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the eid parameter at welcome.php. |
| CVE-2022-32302 | HIGH | 8.8 | 0.9% | Jun 15, 2022 | Theme Park Ticketing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edit_ti... |
| CVE-2022-32300 | HIGH | 8.8 | 1.3% | Jun 15, 2022 | YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Actio... |
| CVE-2022-32299 | HIGH | 8.8 | 1.0% | Jun 15, 2022 | YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/... |
| CVE-2022-32157 | HIGH | 7.5 | 1.2% | Jun 15, 2022 | Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Reme... |
| CVE-2022-32156 | HIGH | 8.1 | 0.7% | Jun 15, 2022 | In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not valida... |
| CVE-2022-32155 | HIGH | 7.5 | 1.8% | Jun 15, 2022 | In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it... |
| CVE-2022-32154 | HIGH | 8.1 | 1.2% | Jun 15, 2022 | Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token... |
| CVE-2022-32153 | HIGH | 8.1 | 0.8% | Jun 15, 2022 | Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did ... |
| CVE-2022-32152 | HIGH | 7.2 | 0.8% | Jun 15, 2022 | Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did ... |
| CVE-2022-29437 | HIGH | 8.8 | 0.4% | Jun 15, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress. |
| CVE-2022-33140 | HIGH | 8.8 | 3.6% | Jun 15, 2022 | The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not ne... |
| CVE-2022-20209 | HIGH | 7.5 | 0.7% | Jun 15, 2022 | In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to a heap buffer overfl... |
| CVE-2022-20207 | HIGH | 7.8 | 0.1% | Jun 15, 2022 | In static definitions of GattServiceConfig.java, there is a possible permission bypass due to an insecure default value.... |
| CVE-2022-20204 | HIGH | 7.8 | 0.1% | Jun 15, 2022 | In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug r... |
| CVE-2022-20197 | HIGH | 7.8 | 0.1% | Jun 15, 2022 | In recycle of Parcel.java, there is a possible way to start foreground activity from background due to a permissions byp... |
| CVE-2022-20194 | HIGH | 7.8 | 0.1% | Jun 15, 2022 | In onCreate of ChooseLockGeneric.java, there is a possible permission bypass. This could lead to local escalation of pri... |
| CVE-2022-20193 | HIGH | 7.3 | 0.1% | Jun 15, 2022 | In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to ... |
| CVE-2022-20192 | HIGH | 7.8 | 0.1% | Jun 15, 2022 | In grantEmbeddedWindowFocus of WindowManagerService.java, there is a possible way to change an input channel for embedde... |
| CVE-2022-20190 | HIGH | 7.5 | 0.4% | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-208744915References: N/A |
| CVE-2022-20188 | HIGH | 7.5 | 0.4% | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-207254598References: N/A |
| CVE-2022-20186 | HIGH | 7.8 | 0.5% | Jun 15, 2022 | In kbase_mem_alias of mali_kbase_mem_linux.c, there is a possible arbitrary code execution due to improper input validat... |
| CVE-2022-20184 | HIGH | 7.5 | 0.4% | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-209153114References: N/A |
| CVE-2022-20181 | HIGH | 7.5 | 0.4% | Jun 15, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-210936609References: N/A |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now