2022 CVE Vulnerabilities
27,541 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30616 | HIGH | 7.2 | 0.8% | Aug 1, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to pl... |
| CVE-2022-2591 | HIGH | 7.5 | 6.4% | Aug 1, 2022 | A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the fil... |
| CVE-2022-22505 | HIGH | 7.5 | 0.7% | Aug 1, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM tenant credentia... |
| CVE-2022-22334 | MEDIUM | 4.3 | 0.4% | Aug 1, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access information from a tenant of whic... |
| CVE-2022-22326 | LOW | 3.3 | 0.2% | Aug 1, 2022 | IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could all... |
| CVE-2022-33994 | LOW | 3 | 0.6% | Jul 30, 2022 | The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "... |
| CVE-2022-36336 | HIGH | 7.8 | 0.5% | Jul 30, 2022 | A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents ... |
| CVE-2022-35234 | HIGH | 7.1 | 0.3% | Jul 30, 2022 | Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerabilit... |
| CVE-2022-33158 | HIGH | 7.8 | 0.3% | Jul 30, 2022 | Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders i... |
| CVE-2022-30083 | CRITICAL | 9.8 | 1.0% | Jul 30, 2022 | EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application appears to evaluate user in... |
| CVE-2022-34531 | CRITICAL | 9.8 | 22.5% | Jul 29, 2022 | DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php. |
| CVE-2022-34528 | HIGH | 8.8 | 1.3% | Jul 29, 2022 | D-Link DSL-3782 v1.03 and below was discovered to contain a stack overflow via the function getAttrValue. |
| CVE-2022-34527 | HIGH | 8.8 | 4.1% | Jul 29, 2022 | D-Link DSL-3782 v1.03 and below was discovered to contain a command injection vulnerability via the function byte_4C0160... |
| CVE-2022-34526 | MEDIUM | 6.5 | 1.4% | Jul 29, 2022 | A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers ... |
| CVE-2022-34496 | CRITICAL | 9.8 | 0.9% | Jul 29, 2022 | Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature. |
| CVE-2022-36447 | HIGH | 7.5 | 0.7% | Jul 29, 2022 | An inflation issue was discovered in Chia Network CAT1 Standard 1.0.0. Previously minted tokens minted on the Chia block... |
| CVE-2022-2324 | HIGH | 7.5 | 0.5% | Jul 29, 2022 | Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture AT... |
| CVE-2022-22280 | CRITICAL | 9.8 | 9.3% | Jul 29, 2022 | Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerabilit... |
| CVE-2022-2323 | HIGH | 8.8 | 1.2% | Jul 29, 2022 | Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remot... |
| CVE-2022-27866 | HIGH | 7.8 | 0.2% | Jul 29, 2022 | A maliciously crafted TIFF file when consumed through DesignReview.exe application can be forced to read beyond allocate... |
| CVE-2022-27865 | HIGH | 7.8 | 0.2% | Jul 29, 2022 | A maliciously crafted TGA or PCX file may be used to write beyond the allocated buffer through DesignReview.exe applicat... |
| CVE-2022-27864 | HIGH | 8.8 | 0.9% | Jul 29, 2022 | A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PD... |
| CVE-2022-36378 | MEDIUM | 4.8 | 0.4% | Jul 29, 2022 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating ... |
| CVE-2022-2414 | HIGH | 7.5 | 85.3% | Jul 29, 2022 | Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a... |
| CVE-2022-23004 | MEDIUM | 5.3 | 0.6% | Jul 29, 2022 | When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate o... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now