2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34971HIGH8.8An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to exec...
CVE-2022-34612MEDIUM5.5Rizin v0.4.0 and below was discovered to contain an integer overflow via the function get_long_object(). This vulnerabil...
CVE-2022-34611MEDIUM5.4A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers...
CVE-2022-34594MEDIUM4.8Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the comp...
CVE-2022-36129CRITICAL9.1HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthent...
CVE-2022-30276HIGH7.5The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway ...
CVE-2022-30274CRITICAL9.8The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio ga...
CVE-2022-30272HIGH7.2The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ...
CVE-2022-30271CRITICAL9.8The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /...
CVE-2022-30270CRITICAL9.8The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This in...
CVE-2022-30269HIGH8.8Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation...
CVE-2022-31207CRITICAL9.8The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic auth...
CVE-2022-31206CRITICAL9.8The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryp...
CVE-2022-31205HIGH7.5In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in...
CVE-2022-31204HIGH7.5Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection ...
CVE-2022-30275HIGH7.5The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to co...
CVE-2022-30273CRITICAL9.8The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Leg...
CVE-2022-29965MEDIUM5.5The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access...
CVE-2022-29964MEDIUM5.5The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC S...
CVE-2022-29963MEDIUM5.5The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET...
CVE-2022-29962MEDIUM5.5The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP ha...
CVE-2022-29960MEDIUM5.5Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bris...
CVE-2022-29958CRITICAL9.8JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protoco...
CVE-2022-29957HIGH7.8The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several pr...
CVE-2022-29953CRITICAL9.8The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now