2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24044 | HIGH | 7.5 | 0.8% | May 20, 2022 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.... |
| CVE-2022-1784 | HIGH | 7.5 | 1.7% | May 20, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8. |
| CVE-2022-30551 | HIGH | 7.5 | 2.2% | May 20, 2022 | OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending cr... |
| CVE-2022-25227 | HIGH | 8.8 | 0.6% | May 20, 2022 | Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged re... |
| CVE-2022-28964 | HIGH | 7.1 | 0.2% | May 20, 2022 | An arbitrary file write vulnerability in Avast Premium Security before v21.11.2500 (build 21.11.6809.528) allows attacke... |
| CVE-2022-21500 | HIGH | 7.5 | 70.6% | May 20, 2022 | Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Ea... |
| CVE-2022-29304 | HIGH | 8.8 | 0.8% | May 19, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /classes/master.php?f=delete_ Facility. |
| CVE-2022-28961 | HIGH | 8.8 | 1.5% | May 19, 2022 | Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the... |
| CVE-2022-28960 | HIGH | 8.8 | 1.8% | May 19, 2022 | A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups paramet... |
| CVE-2022-28948 | HIGH | 7.5 | 3.5% | May 19, 2022 | An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid inpu... |
| CVE-2022-28946 | HIGH | 7.5 | 0.9% | May 19, 2022 | An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret eve... |
| CVE-2022-30618 | HIGH | 7.5 | 0.9% | May 19, 2022 | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and passw... |
| CVE-2022-30617 | HIGH | 8.8 | 1.3% | May 19, 2022 | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and passw... |
| CVE-2022-1423 | HIGH | 8.8 | 1.4% | May 19, 2022 | Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 1... |
| CVE-2022-1413 | HIGH | 7.5 | 0.9% | May 19, 2022 | Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0... |
| CVE-2022-29446 | HIGH | 7.2 | 1.0% | May 19, 2022 | Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugi... |
| CVE-2022-1796 | HIGH | 7.8 | 1.1% | May 19, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2.4979. |
| CVE-2022-30018 | HIGH | 8.8 | 1.0% | May 19, 2022 | Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverab... |
| CVE-2022-1785 | HIGH | 7.8 | 0.5% | May 19, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977. |
| CVE-2022-1183 | HIGH | 7.5 | 4.5% | May 19, 2022 | On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerab... |
| CVE-2022-1670 | HIGH | 7.5 | 0.8% | May 19, 2022 | When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of ... |
| CVE-2022-30138 | HIGH | 7.8 | 1.0% | May 18, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-29229 | HIGH | 7.2 | 0.3% | May 18, 2022 | CaSS is a Competency and Skills System. CaSS Library, (npm:cassproject) has a missing cryptographic step when storing cr... |
| CVE-2022-30994 | HIGH | 7.5 | 0.5% | May 18, 2022 | Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows)... |
| CVE-2022-30993 | HIGH | 7.5 | 0.5% | May 18, 2022 | Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, W... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now