2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30695 | HIGH | 7.8 | 0.2% | May 16, 2022 | Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected... |
| CVE-2022-1679 | HIGH | 7.8 | 0.8% | May 16, 2022 | A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k... |
| CVE-2022-30523 | HIGH | 7.8 | 0.4% | May 16, 2022 | Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalat... |
| CVE-2022-1721 | HIGH | 7.5 | 2.1% | May 16, 2022 | Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web appli... |
| CVE-2022-1713 | HIGH | 7.5 | 8.7% | May 16, 2022 | SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read... |
| CVE-2022-1409 | HIGH | 7.2 | 1.4% | May 16, 2022 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high... |
| CVE-2022-1182 | HIGH | 8.8 | 1.3% | May 16, 2022 | The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using... |
| CVE-2022-1103 | HIGH | 8.8 | 14.3% | May 16, 2022 | The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary fi... |
| CVE-2022-0573 | HIGH | 8.8 | 1.9% | May 16, 2022 | JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead ... |
| CVE-2022-29623 | HIGH | 7.8 | 1.2% | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to... |
| CVE-2022-30012 | HIGH | 7.5 | 1.7% | May 16, 2022 | In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple paramete... |
| CVE-2022-30782 | HIGH | 7.5 | 1.0% | May 16, 2022 | Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secu... |
| CVE-2022-29588 | HIGH | 7.5 | 1.6% | May 16, 2022 | Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS... |
| CVE-2022-29586 | HIGH | 7.4 | 0.4% | May 16, 2022 | Konica Minolta bizhub MFP devices before 2022-04-14 allow a Sandbox Escape. An attacker must attach a keyboard to a USB ... |
| CVE-2022-30781 | HIGH | 7.5 | 87.7% | May 16, 2022 | Gitea before 1.16.7 does not escape git fetch remote. |
| CVE-2022-30763 | HIGH | 7.5 | 1.7% | May 16, 2022 | Janet before 1.22.0 mishandles arrays. |
| CVE-2022-30049 | HIGH | 7.5 | 1.0% | May 15, 2022 | A Server-Side Request Forgery (SSRF) in Rebuild v2.8.3 allows attackers to obtain the real IP address and scan Intranet ... |
| CVE-2022-28937 | HIGH | 7.5 | 1.1% | May 15, 2022 | FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an ... |
| CVE-2022-28936 | HIGH | 7.5 | 0.9% | May 15, 2022 | FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow a... |
| CVE-2022-30708 | HIGH | 8.8 | 3.3% | May 15, 2022 | Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually creat... |
| CVE-2022-25862 | HIGH | 7.5 | 0.7% | May 13, 2022 | This affects the package sds from 0.0.0. The library could be tricked into adding or modifying properties of the Object.... |
| CVE-2022-22281 | HIGH | 7.8 | 0.5% | May 13, 2022 | A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earl... |
| CVE-2022-1701 | HIGH | 7.5 | 4.4% | May 13, 2022 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key ... |
| CVE-2022-22252 | HIGH | 7.5 | 0.6% | May 13, 2022 | The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect system stability. |
| CVE-2022-30417 | HIGH | 7.2 | 0.9% | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via ctpms/admin/?page=user/manage_user&id=. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now