2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26138 | CRITICAL | 9.8 | 98.2% | Jul 20, 2022 | The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th... |
| CVE-2022-26137 | HIGH | 8.8 | 1.9% | Jul 20, 2022 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Fil... |
| CVE-2022-26136 | CRITICAL | 9.8 | 4.2% | Jul 20, 2022 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used ... |
| CVE-2022-22424 | MEDIUM | 5.5 | 0.2% | Jul 20, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to ... |
| CVE-2022-34049 | MEDIUM | 5.3 | 2.2% | Jul 20, 2022 | An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files a... |
| CVE-2022-34048 | MEDIUM | 6.1 | 5.1% | Jul 20, 2022 | Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via th... |
| CVE-2022-34047 | HIGH | 7.5 | 17.4% | Jul 20, 2022 | An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via v... |
| CVE-2022-34046 | HIGH | 7.5 | 16.6% | Jul 20, 2022 | An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via vie... |
| CVE-2022-34045 | CRITICAL | 9.8 | 2.4% | Jul 20, 2022 | Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configurati... |
| CVE-2022-34042 | HIGH | 7.2 | 0.8% | Jul 20, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /... |
| CVE-2022-33320 | HIGH | 7.8 | 0.4% | Jul 20, 2022 | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi E... |
| CVE-2022-33319 | CRITICAL | 9.1 | 1.3% | Jul 20, 2022 | Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics... |
| CVE-2022-33318 | CRITICAL | 9.8 | 45.8% | Jul 20, 2022 | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi E... |
| CVE-2022-33317 | HIGH | 7.8 | 0.3% | Jul 20, 2022 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 t... |
| CVE-2022-33316 | HIGH | 7.8 | 0.3% | Jul 20, 2022 | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi E... |
| CVE-2022-33315 | HIGH | 7.8 | 0.3% | Jul 20, 2022 | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi E... |
| CVE-2022-29834 | HIGH | 7.5 | 1.3% | Jul 20, 2022 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENE... |
| CVE-2022-34150 | MEDIUM | 5.4 | 0.6% | Jul 20, 2022 | The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on end... |
| CVE-2022-33944 | MEDIUM | 6.5 | 0.9% | Jul 20, 2022 | The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on en... |
| CVE-2022-2199 | MEDIUM | 6.1 | 0.6% | Jul 20, 2022 | The main MiCODUS MV720 GPS tracker web server has a reflected cross-site scripting vulnerability that could allow an att... |
| CVE-2022-2179 | MEDIUM | 6.5 | 1.1% | Jul 20, 2022 | The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in th... |
| CVE-2022-2141 | CRITICAL | 9.8 | 1.2% | Jul 20, 2022 | SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication. |
| CVE-2022-2107 | CRITICAL | 9.8 | 1.2% | Jul 20, 2022 | The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master ... |
| CVE-2022-1766 | HIGH | 7.5 | 0.6% | Jul 20, 2022 | Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. ... |
| CVE-2022-1264 | HIGH | 8.8 | 0.8% | Jul 20, 2022 | The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now