2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31028 | HIGH | 7.5 | 2.8% | Jun 7, 2022 | MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with versi... |
| CVE-2022-29564 | HIGH | 7.5 | 0.9% | Jun 7, 2022 | Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in ... |
| CVE-2022-27438 | HIGH | 8.1 | 2.4% | Jun 6, 2022 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced... |
| CVE-2022-30469 | HIGH | 8.8 | 1.4% | Jun 6, 2022 | In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman§ion=get&page... |
| CVE-2022-29631 | HIGH | 7.5 | 0.9% | Jun 6, 2022 | Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequ... |
| CVE-2022-30587 | HIGH | 7.5 | 0.8% | Jun 6, 2022 | Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure. |
| CVE-2022-32275 | HIGH | 7.5 | 8.5% | Jun 6, 2022 | Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /..... |
| CVE-2022-30586 | HIGH | 7.2 | 1.2% | Jun 6, 2022 | Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution. |
| CVE-2022-22396 | HIGH | 7.5 | 0.7% | Jun 6, 2022 | Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certa... |
| CVE-2022-23712 | HIGH | 7.5 | 7.4% | Jun 6, 2022 | A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could fo... |
| CVE-2022-21757 | HIGH | 7.5 | 0.5% | Jun 6, 2022 | In WIFI Firmware, there is a possible system crash due to a missing count check. This could lead to remote denial of ser... |
| CVE-2022-21745 | HIGH | 8.8 | 0.4% | Jun 6, 2022 | In WIFI Firmware, there is a possible memory corruption due to a use after free. This could lead to remote escalation of... |
| CVE-2022-1680 | HIGH | 8.8 | 15.5% | Jun 6, 2022 | An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all... |
| CVE-2022-31486 | HIGH | 8.8 | 1.2% | Jun 6, 2022 | An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell co... |
| CVE-2022-31484 | HIGH | 7.5 | 1.0% | Jun 6, 2022 | An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vu... |
| CVE-2022-31483 | HIGH | 8.8 | 1.6% | Jun 6, 2022 | An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the ... |
| CVE-2022-31482 | HIGH | 7.5 | 1.0% | Jun 6, 2022 | An unauthenticated attacker can send a specially crafted unauthenticated HTTP request to the device that can overflow a ... |
| CVE-2022-31480 | HIGH | 7.5 | 0.9% | Jun 6, 2022 | An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of... |
| CVE-2022-1944 | HIGH | 7.1 | 0.5% | Jun 6, 2022 | When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all ver... |
| CVE-2022-30860 | HIGH | 7.2 | 23.0% | Jun 6, 2022 | FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin... |
| CVE-2022-32291 | HIGH | 8.8 | 1.5% | Jun 5, 2022 | In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file)... |
| CVE-2022-29778 | HIGH | 8.8 | 2.5% | Jun 3, 2022 | D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the param... |
| CVE-2022-26493 | HIGH | 8.8 | 0.5% | Jun 3, 2022 | Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorizati... |
| CVE-2022-1987 | HIGH | 8.1 | 0.8% | Jun 3, 2022 | Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. |
| CVE-2022-32268 | HIGH | 8.8 | 2.1% | Jun 3, 2022 | StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST c... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now