2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-33891 | HIGH | 8.8 | 93.0% | Jul 18, 2022 | The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authen... |
| CVE-2022-27434 | CRITICAL | 9.8 | 1.1% | Jul 18, 2022 | UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileN... |
| CVE-2022-33903 | HIGH | 7.5 | 1.1% | Jul 17, 2022 | Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation. |
| CVE-2022-32985 | CRITICAL | 9.8 | 1.1% | Jul 17, 2022 | libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on ... |
| CVE-2022-31213 | HIGH | 7.5 | 1.7% | Jul 17, 2022 | An issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malfo... |
| CVE-2022-31212 | HIGH | 7.5 | 1.7% | Jul 17, 2022 | An issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. ... |
| CVE-2022-31211 | CRITICAL | 9.8 | 1.5% | Jul 17, 2022 | An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default. |
| CVE-2022-31210 | CRITICAL | 9.8 | 1.0% | Jul 17, 2022 | An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains ... |
| CVE-2022-31209 | CRITICAL | 9.8 | 1.2% | Jul 17, 2022 | An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The firmware contains a potential buffer overflow by calling strcp... |
| CVE-2022-31208 | HIGH | 8.8 | 1.3% | Jul 17, 2022 | An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary comm... |
| CVE-2022-31202 | MEDIUM | 6.5 | 1.2% | Jul 17, 2022 | The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via e... |
| CVE-2022-31201 | MEDIUM | 5.4 | 0.5% | Jul 17, 2022 | SoftGuard Web (SGW) before 5.1.5 allows HTML injection. |
| CVE-2022-30982 | MEDIUM | 5.4 | 0.5% | Jul 17, 2022 | An issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username... |
| CVE-2022-30981 | HIGH | 8.8 | 1.1% | Jul 17, 2022 | An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserial... |
| CVE-2022-28809 | HIGH | 7.8 | 0.4% | Jul 17, 2022 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists w... |
| CVE-2022-28808 | HIGH | 7.8 | 0.4% | Jul 17, 2022 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists w... |
| CVE-2022-28807 | HIGH | 7.8 | 0.4% | Jul 17, 2022 | An issue was discovered in Open Design Alliance Drawings SDK before 2023.2. An Out-of-Bounds Read vulnerability exists w... |
| CVE-2022-26482 | HIGH | 7.2 | 22.3% | Jul 17, 2022 | An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an a... |
| CVE-2022-26481 | HIGH | 8.8 | 1.6% | Jul 17, 2022 | An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificat... |
| CVE-2022-26479 | CRITICAL | 9.8 | 1.7% | Jul 17, 2022 | An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created v... |
| CVE-2022-32263 | HIGH | 7.5 | 0.9% | Jul 17, 2022 | Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719. |
| CVE-2022-29286 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because ... |
| CVE-2022-26352 | CRITICAL | 9.8 | 91.5% | Jul 17, 2022 | An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form req... |
| CVE-2022-30622 | HIGH | 7.3 | 0.2% | Jul 17, 2022 | Disclosure of information - the system allows you to view usernames and passwords without permissions, thus it will be p... |
| CVE-2022-27937 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now