2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30238 | HIGH | 8.8 | 0.9% | Jun 2, 2022 | A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when... |
| CVE-2022-30237 | HIGH | 7.5 | 0.3% | Jun 2, 2022 | A CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be r... |
| CVE-2022-30236 | HIGH | 8.2 | 0.7% | Jun 2, 2022 | A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an... |
| CVE-2022-30232 | HIGH | 8.8 | 1.1% | Jun 2, 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attack... |
| CVE-2022-29594 | HIGH | 7.8 | 0.3% | Jun 2, 2022 | eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. |
| CVE-2022-31463 | HIGH | 7.1 | 1.0% | Jun 2, 2022 | Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authenticatio... |
| CVE-2022-31462 | HIGH | 8.8 | 0.8% | Jun 2, 2022 | Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial nu... |
| CVE-2022-31460 | HIGH | 7.4 | 3.4% | Jun 2, 2022 | Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a cer... |
| CVE-2022-32250 | HIGH | 7.8 | 3.1% | Jun 2, 2022 | net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces... |
| CVE-2022-26868 | HIGH | 7.8 | 0.4% | Jun 2, 2022 | Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated ... |
| CVE-2022-26867 | HIGH | 8 | 0.6% | Jun 2, 2022 | PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, with... |
| CVE-2022-22557 | HIGH | 7.8 | 0.2% | Jun 2, 2022 | PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x ... |
| CVE-2022-22556 | HIGH | 7.5 | 1.2% | Jun 2, 2022 | Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unaut... |
| CVE-2022-31023 | HIGH | 7.5 | 1.2% | Jun 2, 2022 | Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error mess... |
| CVE-2022-31018 | HIGH | 7.5 | 1.6% | Jun 2, 2022 | Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2... |
| CVE-2022-32028 | HIGH | 7.2 | 4.9% | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php... |
| CVE-2022-32027 | HIGH | 7.2 | 0.9% | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/index.php?page=... |
| CVE-2022-32026 | HIGH | 7.2 | 5.3% | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.... |
| CVE-2022-32025 | HIGH | 7.2 | 4.5% | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id... |
| CVE-2022-32024 | HIGH | 7.2 | 4.5% | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=. |
| CVE-2022-32022 | HIGH | 7.2 | 4.9% | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?act... |
| CVE-2022-32021 | HIGH | 7.2 | 0.9% | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_movement... |
| CVE-2022-32018 | HIGH | 7.2 | 4.5% | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=. |
| CVE-2022-32017 | HIGH | 7.2 | 0.9% | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bytitle. |
| CVE-2022-32016 | HIGH | 7.2 | 0.9% | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bycompany. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now