2022 CVE Vulnerabilities
27,541 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34568 | HIGH | 7.5 | 0.9% | Jul 28, 2022 | SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c. |
| CVE-2022-30287 | HIGH | 8 | 70.3% | Jul 28, 2022 | Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instan... |
| CVE-2022-2399 | HIGH | 8.8 | 0.6% | Jul 28, 2022 | Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap c... |
| CVE-2022-29558 | HIGH | 8.8 | 1.2% | Jul 28, 2022 | Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface. |
| CVE-2022-29360 | MEDIUM | 5.4 | 1.0% | Jul 28, 2022 | The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message. |
| CVE-2022-34593 | HIGH | 7.5 | 0.6% | Jul 28, 2022 | DPTech VPN v8.1.28.0 was discovered to contain an arbitrary file read vulnerability. |
| CVE-2022-34578 | HIGH | 7.2 | 1.0% | Jul 28, 2022 | Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Brandin... |
| CVE-2022-2564 | CRITICAL | 9.8 | 32.7% | Jul 28, 2022 | Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6. |
| CVE-2022-30320 | MEDIUM | 4.3 | 0.2% | Jul 28, 2022 | Saia Burgess Controls (SBC) PCD through 2022-05-06 uses a Broken or Risky Cryptographic Algorithm. According to FSCT-202... |
| CVE-2022-30319 | HIGH | 8.1 | 0.6% | Jul 28, 2022 | Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. According to FSCT-2022-0062, there is a... |
| CVE-2022-30316 | MEDIUM | 6.8 | 0.3% | Jul 28, 2022 | Honeywell Experion PKS Safety Manager 5.02 has Insufficient Verification of Data Authenticity. According to FSCT-2022-00... |
| CVE-2022-30315 | CRITICAL | 9.8 | 0.7% | Jul 28, 2022 | Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity... |
| CVE-2022-30314 | MEDIUM | 4.6 | 0.3% | Jul 28, 2022 | Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywel... |
| CVE-2022-30313 | HIGH | 7.5 | 0.7% | Jul 28, 2022 | Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According t... |
| CVE-2022-35882 | MEDIUM | 4.8 | 0.4% | Jul 28, 2022 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in GS Plugins GS Testimonial ... |
| CVE-2022-2553 | MEDIUM | 6.5 | 0.9% | Jul 28, 2022 | The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node... |
| CVE-2022-1948 | MEDIUM | 5.4 | 0.8% | Jul 28, 2022 | An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of in... |
| CVE-2022-1805 | HIGH | 8.1 | 0.5% | Jul 28, 2022 | When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero C... |
| CVE-2022-27509 | MEDIUM | 6.1 | 0.4% | Jul 28, 2022 | Unauthenticated redirection to a malicious website |
| CVE-2022-37010 | LOW | 3.3 | 0.2% | Jul 28, 2022 | In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was misse... |
| CVE-2022-37009 | HIGH | 7.8 | 0.2% | Jul 28, 2022 | In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible |
| CVE-2022-36364 | HIGH | 8.8 | 2.2% | Jul 28, 2022 | Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` con... |
| CVE-2022-27611 | HIGH | 8.1 | 0.9% | Jul 28, 2022 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno... |
| CVE-2022-27614 | HIGH | 7.5 | 0.8% | Jul 28, 2022 | Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1... |
| CVE-2022-27613 | HIGH | 8.8 | 0.9% | Jul 28, 2022 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component i... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now