2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22521 | HIGH | 7.3 | 0.5% | Apr 27, 2022 | In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowi... |
| CVE-2022-29505 | HIGH | 7.8 | 0.5% | Apr 27, 2022 | Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that cou... |
| CVE-2022-27905 | HIGH | 7.2 | 1.0% | Apr 27, 2022 | In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require ... |
| CVE-2022-27239 | HIGH | 7.8 | 0.6% | Apr 27, 2022 | In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could le... |
| CVE-2022-29701 | HIGH | 7.5 | 1.0% | Apr 27, 2022 | A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount o... |
| CVE-2022-29700 | HIGH | 7.5 | 0.9% | Apr 27, 2022 | A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cau... |
| CVE-2022-28085 | HIGH | 7.8 | 1.1% | Apr 27, 2022 | A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lea... |
| CVE-2022-28918 | HIGH | 8.1 | 1.0% | Apr 26, 2022 | GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=... |
| CVE-2022-28528 | HIGH | 8.8 | 1.2% | Apr 26, 2022 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&p... |
| CVE-2022-28527 | HIGH | 8.1 | 1.0% | Apr 26, 2022 | dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/... |
| CVE-2022-28525 | HIGH | 8.8 | 0.9% | Apr 26, 2022 | ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_use... |
| CVE-2022-28523 | HIGH | 8.1 | 1.0% | Apr 26, 2022 | HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete. |
| CVE-2022-28059 | HIGH | 8.1 | 1.2% | Apr 26, 2022 | Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php. |
| CVE-2022-28058 | HIGH | 8.1 | 1.2% | Apr 26, 2022 | Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php. |
| CVE-2022-24882 | HIGH | 7.5 | 2.7% | Apr 26, 2022 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM)... |
| CVE-2022-23942 | HIGH | 7.5 | 3.1% | Apr 26, 2022 | Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lea... |
| CVE-2022-29419 | HIGH | 8.8 | 0.8% | Apr 25, 2022 | SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with... |
| CVE-2022-1441 | HIGH | 7.8 | 0.9% | Apr 25, 2022 | MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to pars... |
| CVE-2022-24792 | HIGH | 7.5 | 1.8% | Apr 25, 2022 | PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects... |
| CVE-2022-22392 | HIGH | 7.8 | 2.0% | Apr 25, 2022 | IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an... |
| CVE-2022-1392 | HIGH | 7.5 | 11.1% | Apr 25, 2022 | The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include state... |
| CVE-2022-0656 | HIGH | 7.5 | 7.7% | Apr 25, 2022 | The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url... |
| CVE-2022-26111 | HIGH | 8.8 | 4.0% | Apr 25, 2022 | The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creati... |
| CVE-2022-28053 | HIGH | 8.8 | 1.2% | Apr 25, 2022 | Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerabi... |
| CVE-2022-28871 | HIGH | 7.5 | 0.5% | Apr 25, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now