2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29662 | HIGH | 7.2 | 0.8% | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.ph... |
| CVE-2022-29661 | HIGH | 7.2 | 0.9% | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /ad... |
| CVE-2022-29721 | HIGH | 7.5 | 1.0% | May 26, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resu... |
| CVE-2022-29720 | HIGH | 7.5 | 0.9% | May 26, 2022 | 74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Downlo... |
| CVE-2022-27169 | HIGH | 7.5 | 1.6% | May 25, 2022 | An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Softw... |
| CVE-2022-26303 | HIGH | 7.5 | 1.2% | May 25, 2022 | An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Softwar... |
| CVE-2022-26077 | HIGH | 7.5 | 1.1% | May 25, 2022 | A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications fu... |
| CVE-2022-26067 | HIGH | 7.5 | 1.2% | May 25, 2022 | An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation So... |
| CVE-2022-26043 | HIGH | 7.5 | 1.2% | May 25, 2022 | An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Sof... |
| CVE-2022-26026 | HIGH | 7.5 | 1.1% | May 25, 2022 | A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software ... |
| CVE-2022-29248 | HIGH | 8.1 | 1.2% | May 25, 2022 | Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middlewar... |
| CVE-2022-30428 | HIGH | 7.5 | 1.1% | May 25, 2022 | In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading. |
| CVE-2022-30427 | HIGH | 7.5 | 1.4% | May 25, 2022 | In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal. |
| CVE-2022-27305 | HIGH | 8.8 | 1.0% | May 25, 2022 | Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to se... |
| CVE-2022-1678 | HIGH | 7.5 | 2.9% | May 25, 2022 | An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can le... |
| CVE-2022-22127 | HIGH | 7.2 | 1.0% | May 25, 2022 | Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers u... |
| CVE-2022-29651 | HIGH | 7.2 | 1.4% | May 25, 2022 | An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers... |
| CVE-2022-1851 | HIGH | 7.8 | 1.6% | May 25, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-30323 | HIGH | 8.6 | 1.3% | May 25, 2022 | go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0. |
| CVE-2022-30322 | HIGH | 8.6 | 1.3% | May 25, 2022 | go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP response... |
| CVE-2022-30321 | HIGH | 8.6 | 3.1% | May 25, 2022 | go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and com... |
| CVE-2022-1883 | HIGH | 8.8 | 6.4% | May 25, 2022 | SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0. |
| CVE-2022-1815 | HIGH | 7.5 | 5.7% | May 25, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2. |
| CVE-2022-22497 | HIGH | 7.5 | 1.1% | May 24, 2022 | IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-F... |
| CVE-2022-29333 | HIGH | 7.8 | 0.9% | May 24, 2022 | A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now