2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34971 | HIGH | 8.8 | 1.0% | Jul 27, 2022 | An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to exec... |
| CVE-2022-34612 | MEDIUM | 5.5 | 0.4% | Jul 27, 2022 | Rizin v0.4.0 and below was discovered to contain an integer overflow via the function get_long_object(). This vulnerabil... |
| CVE-2022-34611 | MEDIUM | 5.4 | 0.6% | Jul 27, 2022 | A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers... |
| CVE-2022-34594 | MEDIUM | 4.8 | 0.4% | Jul 27, 2022 | Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the comp... |
| CVE-2022-36129 | CRITICAL | 9.1 | 1.3% | Jul 26, 2022 | HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthent... |
| CVE-2022-30276 | HIGH | 7.5 | 0.6% | Jul 26, 2022 | The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway ... |
| CVE-2022-30274 | CRITICAL | 9.8 | 0.5% | Jul 26, 2022 | The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio ga... |
| CVE-2022-30272 | HIGH | 7.2 | 0.4% | Jul 26, 2022 | The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ... |
| CVE-2022-30271 | CRITICAL | 9.8 | 0.8% | Jul 26, 2022 | The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /... |
| CVE-2022-30270 | CRITICAL | 9.8 | 0.7% | Jul 26, 2022 | The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This in... |
| CVE-2022-30269 | HIGH | 8.8 | 0.4% | Jul 26, 2022 | Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation... |
| CVE-2022-31207 | CRITICAL | 9.8 | 0.7% | Jul 26, 2022 | The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic auth... |
| CVE-2022-31206 | CRITICAL | 9.8 | 0.8% | Jul 26, 2022 | The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryp... |
| CVE-2022-31205 | HIGH | 7.5 | 0.5% | Jul 26, 2022 | In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in... |
| CVE-2022-31204 | HIGH | 7.5 | 0.5% | Jul 26, 2022 | Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection ... |
| CVE-2022-30275 | HIGH | 7.5 | 0.5% | Jul 26, 2022 | The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to co... |
| CVE-2022-30273 | CRITICAL | 9.8 | 0.3% | Jul 26, 2022 | The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Leg... |
| CVE-2022-29965 | MEDIUM | 5.5 | 0.2% | Jul 26, 2022 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access... |
| CVE-2022-29964 | MEDIUM | 5.5 | 0.2% | Jul 26, 2022 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC S... |
| CVE-2022-29963 | MEDIUM | 5.5 | 0.2% | Jul 26, 2022 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET... |
| CVE-2022-29962 | MEDIUM | 5.5 | 0.2% | Jul 26, 2022 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP ha... |
| CVE-2022-29960 | MEDIUM | 5.5 | 0.4% | Jul 26, 2022 | Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bris... |
| CVE-2022-29958 | CRITICAL | 9.8 | 0.5% | Jul 26, 2022 | JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protoco... |
| CVE-2022-29957 | HIGH | 7.8 | 0.2% | Jul 26, 2022 | The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several pr... |
| CVE-2022-29953 | CRITICAL | 9.8 | 0.8% | Jul 26, 2022 | The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now