2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23050 | HIGH | 7.2 | 4.6% | May 24, 2022 | ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hija... |
| CVE-2022-22977 | HIGH | 7.1 | 0.8% | May 24, 2022 | VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious act... |
| CVE-2022-1669 | HIGH | 8.1 | 0.7% | May 24, 2022 | A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The devi... |
| CVE-2022-22495 | HIGH | 8.8 | 2.1% | May 24, 2022 | IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, w... |
| CVE-2022-29249 | HIGH | 7.5 | 0.7% | May 24, 2022 | JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of loc... |
| CVE-2022-31261 | HIGH | 7.5 | 1.1% | May 24, 2022 | An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML iden... |
| CVE-2022-30843 | HIGH | 8.8 | 0.9% | May 24, 2022 | Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id. |
| CVE-2022-29567 | HIGH | 7.5 | 0.9% | May 24, 2022 | The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communica... |
| CVE-2022-29242 | HIGH | 7.5 | 1.6% | May 24, 2022 | GOST engine is a reference implementation of the Russian GOST crypto algorithms for OpenSSL. TLS clients using GOST engi... |
| CVE-2022-29221 | HIGH | 8.8 | 4.5% | May 24, 2022 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio... |
| CVE-2022-29219 | HIGH | 7.5 | 1.2% | May 24, 2022 | Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a pos... |
| CVE-2022-29217 | HIGH | 7.5 | 1.2% | May 24, 2022 | PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an att... |
| CVE-2022-1850 | HIGH | 8.1 | 1.0% | May 24, 2022 | Path Traversal in GitHub repository filegator/filegator prior to 7.8.0. |
| CVE-2022-30463 | HIGH | 8.8 | 0.9% | May 24, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product. |
| CVE-2022-30459 | HIGH | 8.8 | 0.9% | May 24, 2022 | ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=del... |
| CVE-2022-26532 | HIGH | 7.8 | 4.8% | May 24, 2022 | A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 t... |
| CVE-2022-26531 | HIGH | 7.8 | 5.8% | May 24, 2022 | Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versio... |
| CVE-2022-1839 | HIGH | 8.8 | 0.8% | May 24, 2022 | A vulnerability classified as critical was found in Home Clean Services Management System 1.0. This vulnerability affect... |
| CVE-2022-1838 | HIGH | 7.2 | 0.9% | May 24, 2022 | A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unkn... |
| CVE-2022-1837 | HIGH | 7.2 | 1.1% | May 24, 2022 | A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this ... |
| CVE-2022-29309 | HIGH | 7.5 | 0.9% | May 24, 2022 | mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery. |
| CVE-2022-29305 | HIGH | 8.1 | 0.9% | May 24, 2022 | imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost. |
| CVE-2022-29377 | HIGH | 7.5 | 1.0% | May 24, 2022 | Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.c... |
| CVE-2022-29376 | HIGH | 8.8 | 1.2% | May 23, 2022 | Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing at... |
| CVE-2022-29002 | HIGH | 8.8 | 0.4% | May 23, 2022 | A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now