2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1459 | HIGH | 8.3 | 1.0% | Apr 25, 2022 | Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1. |
| CVE-2022-29603 | HIGH | 8.1 | 1.4% | Apr 25, 2022 | A SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select parameter to multiple API ... |
| CVE-2022-29546 | HIGH | 7.5 | 1.1% | Apr 25, 2022 | HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the... |
| CVE-2022-1452 | HIGH | 7.1 | 0.8% | Apr 24, 2022 | Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7... |
| CVE-2022-1451 | HIGH | 7.1 | 0.8% | Apr 24, 2022 | Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0.... |
| CVE-2022-1427 | HIGH | 7.8 | 0.4% | Apr 23, 2022 | Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary ... |
| CVE-2022-0354 | HIGH | 7.8 | 0.2% | Apr 22, 2022 | A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ab... |
| CVE-2022-0192 | HIGH | 7.8 | 0.2% | Apr 22, 2022 | A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege... |
| CVE-2022-27340 | HIGH | 8.8 | 0.7% | Apr 22, 2022 | MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attack... |
| CVE-2022-29583 | HIGH | 7.8 | 0.3% | Apr 22, 2022 | service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Win... |
| CVE-2022-29582 | HIGH | 7 | 0.8% | Apr 22, 2022 | In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This... |
| CVE-2022-1437 | HIGH | 7.1 | 0.7% | Apr 22, 2022 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data ... |
| CVE-2022-27406 | HIGH | 7.5 | 3.2% | Apr 22, 2022 | FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the func... |
| CVE-2022-27405 | HIGH | 7.5 | 2.7% | Apr 22, 2022 | FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the func... |
| CVE-2022-1429 | HIGH | 7.5 | 64.6% | Apr 22, 2022 | SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capab... |
| CVE-2022-28366 | HIGH | 7.5 | 2.0% | Apr 21, 2022 | Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes ex... |
| CVE-2022-26856 | HIGH | 7.8 | 0.2% | Apr 21, 2022 | Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could p... |
| CVE-2022-24424 | HIGH | 7.5 | 1.6% | Apr 21, 2022 | Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthentic... |
| CVE-2022-24423 | HIGH | 7.5 | 1.5% | Apr 21, 2022 | Dell iDRAC8 versions prior to 2.83.83.83 contain a denial of service vulnerability. A remote unauthenticated attacker co... |
| CVE-2022-28444 | HIGH | 7.5 | 1.5% | Apr 21, 2022 | UCMS v1.6 was discovered to contain an arbitrary file read vulnerability. |
| CVE-2022-28440 | HIGH | 8.8 | 1.6% | Apr 21, 2022 | An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file. |
| CVE-2022-28020 | HIGH | 8.8 | 1.1% | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\posi... |
| CVE-2022-28019 | HIGH | 8.8 | 1.1% | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\empl... |
| CVE-2022-28018 | HIGH | 8.8 | 1.1% | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\sche... |
| CVE-2022-28017 | HIGH | 8.8 | 1.1% | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\over... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now