2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36529 | HIGH | 8.8 | 0.9% | Aug 26, 2022 | Kensite CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities via the name and oldname parameters at... |
| CVE-2022-36522 | MEDIUM | 6.5 | 1.1% | Aug 26, 2022 | Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools... |
| CVE-2022-35714 | MEDIUM | 5.4 | 0.4% | Aug 26, 2022 | IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2022-34303 | MEDIUM | 6.7 | 0.8% | Aug 26, 2022 | A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with... |
| CVE-2022-34302 | MEDIUM | 6.7 | 1.1% | Aug 26, 2022 | A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or ... |
| CVE-2022-34301 | MEDIUM | 6.7 | 0.9% | Aug 26, 2022 | A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass o... |
| CVE-2022-31773 | HIGH | 8.8 | 0.3% | Aug 26, 2022 | IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attac... |
| CVE-2022-0225 | MEDIUM | 5.4 | 2.6% | Aug 26, 2022 | A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name whil... |
| CVE-2022-0217 | HIGH | 7.5 | 4.4% | Aug 26, 2022 | It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML feat... |
| CVE-2022-0216 | MEDIUM | 4.4 | 0.4% | Aug 26, 2022 | A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs whil... |
| CVE-2022-0207 | MEDIUM | 4.7 | 0.2% | Aug 26, 2022 | A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values bei... |
| CVE-2022-0175 | MEDIUM | 5.5 | 0.3% | Aug 26, 2022 | A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when... |
| CVE-2022-0171 | MEDIUM | 5.5 | 0.3% | Aug 26, 2022 | A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-le... |
| CVE-2022-0168 | MEDIUM | 4.4 | 0.3% | Aug 26, 2022 | A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c ... |
| CVE-2022-0084 | HIGH | 7.5 | 1.1% | Aug 26, 2022 | A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a mess... |
| CVE-2022-25625 | HIGH | 8.8 | 0.7% | Aug 26, 2022 | A malicious unauthorized PAM user can access the administration configuration data and change the values. |
| CVE-2022-36521 | HIGH | 7.5 | 0.6% | Aug 26, 2022 | Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts. |
| CVE-2022-37152 | CRITICAL | 9.8 | 0.9% | Aug 26, 2022 | An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob"... |
| CVE-2022-37151 | HIGH | 7.5 | 0.8% | Aug 26, 2022 | There is an unauthorized access vulnerability in Online Diagnostic Lab Management System 1.0. |
| CVE-2022-37150 | MEDIUM | 5.4 | 0.5% | Aug 26, 2022 | An issue was discovered in Online Diagnostic Lab Management System 1.0. There is a stored XSS vulnerability via firstnam... |
| CVE-2022-36683 | CRITICAL | 9.8 | 0.9% | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas... |
| CVE-2022-36682 | CRITICAL | 9.8 | 0.9% | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas... |
| CVE-2022-36681 | CRITICAL | 9.8 | 0.9% | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas... |
| CVE-2022-36680 | CRITICAL | 9.8 | 0.9% | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas... |
| CVE-2022-36679 | CRITICAL | 9.8 | 0.8% | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now