2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29849 | HIGH | 7.8 | 0.3% | May 2, 2022 | In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were s... |
| CVE-2022-28451 | HIGH | 7.5 | 1.5% | May 2, 2022 | nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature. |
| CVE-2022-26068 | HIGH | 7.5 | 1.5% | May 1, 2022 | This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbi... |
| CVE-2022-25850 | HIGH | 7.5 | 1.3% | May 1, 2022 | The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when int... |
| CVE-2022-25844 | HIGH | 7.5 | 4.7% | May 1, 2022 | The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom loc... |
| CVE-2022-25647 | HIGH | 7.5 | 11.6% | May 1, 2022 | The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeRepl... |
| CVE-2022-25645 | HIGH | 8.1 | 1.8% | May 1, 2022 | All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks fo... |
| CVE-2022-21227 | HIGH | 7.5 | 2.0% | May 1, 2022 | The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of th... |
| CVE-2022-21144 | HIGH | 7.5 | 1.8% | May 1, 2022 | This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument t... |
| CVE-2022-1544 | HIGH | 7.8 | 2.3% | May 1, 2022 | Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luya... |
| CVE-2022-28323 | HIGH | 7.5 | 1.3% | Apr 30, 2022 | An issue was discovered in MediaWiki through 1.37.2. The SecurePoll extension allows a leak because sorting by timestamp... |
| CVE-2022-29265 | HIGH | 7.5 | 2.4% | Apr 30, 2022 | Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configu... |
| CVE-2022-29967 | HIGH | 7.5 | 1.5% | Apr 29, 2022 | static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal. |
| CVE-2022-29945 | HIGH | 7.5 | 0.7% | Apr 29, 2022 | DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical locati... |
| CVE-2022-1543 | HIGH | 8.8 | 1.1% | Apr 29, 2022 | Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large e... |
| CVE-2022-29937 | HIGH | 8.8 | 1.5% | Apr 29, 2022 | USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because som... |
| CVE-2022-29936 | HIGH | 8.8 | 2.0% | Apr 29, 2022 | USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/q... |
| CVE-2022-29935 | HIGH | 7.5 | 1.1% | Apr 29, 2022 | USU Oracle Optimization before 5.17.5 allows attackers to discover the quantum credentials via an agent-installer downlo... |
| CVE-2022-29934 | HIGH | 7.8 | 0.3% | Apr 29, 2022 | USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root acc... |
| CVE-2022-29451 | HIGH | 8.8 | 0.6% | Apr 29, 2022 | Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <=... |
| CVE-2022-1403 | HIGH | 7.8 | 0.8% | Apr 29, 2022 | ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing... |
| CVE-2022-1402 | HIGH | 7.1 | 0.8% | Apr 29, 2022 | ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing... |
| CVE-2022-29856 | HIGH | 7.5 | 1.5% | Apr 29, 2022 | A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages. |
| CVE-2022-1353 | HIGH | 7.1 | 0.4% | Apr 29, 2022 | A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a loc... |
| CVE-2022-1227 | HIGH | 8.8 | 4.2% | Apr 29, 2022 | A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public r... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now